ClipBanker

First seen
2018-08-01 00:00:00
Malware type
credential-stealer, trojan, spyware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 13:44:45

Targeted industries: financial-services technology-and-telecommunications

Context

The ClipBanker Trojan is known as an information stealer and spy trojan, it aims to steal and record any type of sensitive information from the infected environment such as browser history, cookies, Outlook data, Skype, Telegram, or cryptocurrency wallet account addresses. The main goal of this threat is to steal confidential information. The ClipBanker uses PowerShell commands for executing malicious activities. The thing that made the ClipBanker unique is its ability to record various banking actions of the user and manipulate them for its own benefit. The distribution method of the ClipBanker is through phishing emails or through social media posts that lure users to download malicious content.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Clipbanker01 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Clipbanker02 (yara-rule)

Reports & references

  • ESET — Eset Threat Report Q22020 (report)
  • Trend Micro — Ioc%20Resource%20For%20Russia Ukraine%20Conflict Related%20Cyberattacks 03032022 (report)
  • ESET — Buhtrap Backdoor Ransomware Advertising Platform (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Clipbanker (report)
  • cynet.com — Threat Research Report Clipbanker 13 Second Attack (report)
  • trustwave.com — Covid 19 Phishing Lure To Steal And Mine Cryptocurrency (report)
  • blog.plainbit.co.kr — Sanae Yuib Seupieopising Meil Bunseog (report)
  • asec.ahnlab.com — 35981 (report)

External references