Skip to main content

Hackers target Windows clipboard to steal cryptocurrency wallet addresses

New email-based malware dubbed as ComboJack is targeting Japanese and American web surfers to steal cryptocurrency during transactions. Once installed and lurking in the background, the malware grabs the victim’s long cryptocurrency wallet address stored in the Windows clipboard. Due to their extreme length, many users simply copy and paste that string of characters, and that is when ComboJack attacks. 

Discovered by researchers at the Palo Alto Networks, it’s a variant of a cryptocurrency stealer called CryptoJack. It grabs the address of a victim’s cryptocurrency wallet coped to the clipboard and replaces it with the address of the hacker’s wallet. Thus, victims believe they are transferring digital currency to their personal virtual wallets when instead they’re unknowingly pasting a different destination into the transaction prior to completion. 

Recommended Videos

CryptoShuffler was the first malware to use this stealing agent in 2017, but solely focused on Bitcoin. In 2018, ComboJack arrives to target not only Bitcoin investors, but Ethereum, Litecoin, Monero, and many other digital currencies. But the route this malware takes can be avoided by simply not opening an emailed attachment from untrusted sources.  

According to the report, victims receive emails regarding a lost passport. The shady message requests that the victim view an attachment that’s supposedly a scanned passport in a PDF format for identification purposes. But once victims open the PDF, they are presented with a single line to open an embedded document. Inside this secondary file is an embedded remote object that attacks a security hole in Windows. 

“An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory,” Microsoft’s database states. “An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” 

The embedded remote object downloads a two-part file, one part containing a self-extracting executable, and a second part containing password-protected components to create and install the final payload: ComboJack. The malware then uses a built-in Windows tool to give it system-level privileges, edits the registry to make sure it remains running in the background and enters into an infinite loop. ComboJack then checks the system clipboard every half second for a cryptocurrency wallet address. 

So why aren’t cryptocurrency users simply manually entering their wallet addresses? Because it’s a pain. Ethereum addresses are 42 characters long while Bitcoin uses 34 characters. The longest is likely Monero, which relies on addresses with characters counts between 95 and 106. This is why users typically copy and paste their addresses, which serves as a virtual gold mine for hackers. 

While the suggestion of manually entering addresses during transactions is out of the question, opening files attached to emails sent from unknown parties is an extremely bad idea. In this case, the big clue starts with the actual poorly written message along with its suspicious attachment. But even after opening the PDF, the request to open another file should be another huge red flag.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Nvidia just dropped a big hint about the RTX 50-series release date
nvidia rtx 4080 review 12

Speculation has been running rampant about Nvidia's launch of next-gen RTX 50-series GPUs, but the company itself just dropped a big hint about when they may show up. Nvidia CEO Jensen Huang is set to take the stage as the keynote speaker of CES 2025 on January 6, where there's a good chance we'll hear about Nvidia's next generation of graphics cards.

Although Nvidia is at the annual tech show each year, Huang -- who recently surpassed the worth of all of Intel -- hasn't made an appearance in five years. The executive will likely focus heavily on AI, as it has catapulted Nvidia to become one of the world's wealthiest companies. But RTX 50-series GPUs should make an appearance, too. Nvidia usually takes advantage of CES to launch new graphics cards.

Read more
I’ve reviewed every AMD and Nvidia GPU this generation — here’s how the two companies stack up
Three graphics cards on a gray background.

Nvidia and AMD make the best graphics cards you can buy, but choosing between them isn't easy. Unlike previous generations, AMD and Nvidia trade blows point-for-point in 2024, and picking a brand to go with isn't as easy as counting the dollars in your wallet.

I've reviewed every graphics card AMD and Nvidia have released this generation, comparing not only raw performance, but also features like DLSS and FSR, ray tracing performance, and how VRAM works in modern games. After dozens of graphics card reviews, here's how AMD and Nvidia stack up against each other in 2024.
Nvidia vs. AMD in 2024

Read more
How to install a graphics card
GPU inside the Dell XPS Desktop 8960.

A graphics card (also referred to as a GPU) is one of the most vital parts of your computer, perhaps second only to your machine’s processor. If you enjoy gaming on your PC, a solid GPU is even more important. After all, you can’t get jaw-dropping graphics and blistering frame rates from an ultra-basic graphics setup.

Read more