New Laplas Clipper Malware Targeting Cryptocurrency Users via SmokeLoader

Share:

Cryptocurrency users are being targeted with a new clipper malware strain dubbed Laplas by means of another malware known as SmokeLoader.

SmokeLoader, which is delivered by means of weaponized documents sent through spear-phishing emails, further acts as a conduit for other commodity trojans like SystemBC and Raccoon Stealer 2.0, according to an analysis from Cyble.

Observed in the wild since circa 2013, SmokeLoader functions as a generic loader capable of distributing additional payloads onto compromised systems, such as information-stealing malware and other implants. In July 2022, it was found to deploy a backdoor called Amadey.

Cyble said it discovered over 180 samples of the Laplas since October 24, 2022, suggesting a wide deployment.

Bild30

Clippers, also called ClipBankers, fall under a category of malware that Microsoft calls cryware, which are designed to steal crypto by keeping close tabs on a victim’s clipboard activity and swapping the original wallet address, if present, with an attacker-controlled address.

Bild31

The goal of clipper malware like Laplas is to hijack a virtual currency transaction intended for a legitimate recipient to that owned by the threat actor.

“Laplas is new clipper malware that generates a wallet address similar to the victim’s wallet address,” the researchers pointed out. “The victim will not notice the difference in the address, which significantly increases the chances of successful clipper activity.”

 

The newest clipper malware offers support for a variety of wallets like Bitcoin, Ethereum, Bitcoin Cash, Litecoin, Dogecoin, Monero, Ripple, Zcash, Dash, Ronin, TRON, Cardano, Cosmos, Tezos, Qtum, and Steam Trade URL. It’s priced from $59 a month to $549 a year.

It also comes with its own web panel that enables its purchasers to get information about the number of infected computers and the active wallet addresses operated by the adversary, in addition to allowing for adding new wallet addresses.

“SmokeLoader is a well-known, highly configurable, effective malware that TAs [threat actors] are actively renovating,” the researchers concluded.

“It is a modular malware, indicating it can get new execution instructions from [command-and-control] servers and download additional malware for expanded functionality. In this case, the TAs use three different malware families for financial gain and other malicious purposes.”

https://thehackernews.com/2022/11/new-laplas-clipper-malware-targeting.html

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:09 am, Jul 8, 2025
weather icon 14°C
L: 13° | H: 15°
few clouds
Humidity: 73 %
Pressure: 1014 mb
Wind: 10 mph WNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 24%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 15°°C 1 mm 100% 11 mph 75 % 1019 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 25°°C 0.13 mm 13% 7 mph 59 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 8 mph 72 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 66 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 11 mph 74 % 1020 mb 0 mm/h
Today 4:00 am
weather icon
12° | 14°°C 1 mm 100% 11 mph 73 % 1015 mb 0 mm/h
Today 7:00 am
weather icon
13° | 14°°C 0.64 mm 64% 9 mph 75 % 1015 mb 0 mm/h
Today 10:00 am
weather icon
17° | 18°°C 0 mm 0% 9 mph 56 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 7 mph 34 % 1018 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 7 mph 29 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 7 mph 29 % 1018 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 4 mph 41 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 5 mph 48 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,791.76
-1.42%
Ethereum(ETH)
€2,153.20
-1.62%
Tether(USDT)
€0.85
-0.02%
XRP(XRP)
€1.93
-0.47%
Solana(SOL)
€126.81
-1.87%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.141996
-3.23%
Shiba Inu(SHIB)
€0.000010
-2.20%
Pepe(PEPE)
€0.000009
-3.34%
Scroll to Top