CryptoShuffler

First seen
2017-10-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:55:35

Targeted industries: financial-services

Context

CryptoShuffler is a Trojan that targets cryptocurrency users by manipulating clipboard contents to redirect payments to attacker-controlled wallets. It primarily aims to steal funds from unsuspecting users by replacing copied wallet addresses with those belonging to the attacker.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cryptoshuffler_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Cryptoshuffler (report)
  • bleepingcomputer.com — Cryptoshuffler Stole 150 000 By Replacing Bitcoin Wallet Ids In Pc Clipboards (report)

External references