Evrial
- First seen
- 2018-01-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:17:13
- Profile updated
- 2026-07-07 15:00:37
Context
Evrial is a credential-stealer malware known for its clipboard hijacking capabilities. It primarily targets cryptocurrency wallet addresses copied to the clipboard and replaces them with the attacker's own address to redirect funds.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Evrial (report)
- bleepingcomputer.com — Evrial Trojan Switches Bitcoin Addresses Copied To Windows Clipboard (report)