SYMBOLCOMMON_NAMEaka. SYNONYMS
win.animate_clipper (Back to overview)

AnimateClipper


According to Check Point Research, AnimateClipper is a cryptocurrency clipper that is delivered through a ClickFix-style phishing chain in which a built-in Windows utility runs a remote scripted page, leading to a bundled Python environment that executes embedded shellcode in memory to load the final payload without writing the unpacked binary to disk. The malware continuously monitors the clipboard for cryptocurrency wallet addresses, identifies the wallet format locally, and silently replaces the copied address with one of many embedded attacker-controlled wallets, enabling transaction hijacking across more than 20 blockchain ecosystems. It resolves its command-and-control server dynamically by querying a smart contract over a public blockchain JSON-RPC endpoint, then communicates over HTTPS for periodic check-ins and to report address-replacement activity. The embedded replacement wallets themselves are stored directly in the binary, and on-chain data indicates the operation has been active since at least mid-2025.

References
2026-06-03Check Point ResearchAlexey Bukhteyev
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
AnimateClipper Remus

There is no Yara-Signature yet.