Technique
Clipboard Hijacking
Also known as: Clipper Malware, Crypto Clipper, Clipboard Stealer, Address Swapper, ClipBanker, Clipboard Data Collection, Pastejacking, Cryware
Monitors clipboard contents to exfiltrate sensitive data (passwords, private keys, credentials) or replace copied cryptocurrency addresses and payment info with attacker-controlled values. Web-based variants (pastejacking) inject hidden commands into copied text via JavaScript.
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Pasted cryptocurrency address differs from copied source - verify first/last 4+ characters before confirming
- Unexpected clipboard content changes when not actively copying
- Unknown background processes accessing clipboard API with no visible window
- Endpoint protection alerts for clipper signatures (Agent Tesla, Remcos, ClipBanker)
- Mobile apps requesting clipboard access permissions unexpectedly
- Transaction sent to wrong address despite copying correct one
- Browser extensions requesting clipboard permissions without clear need
- Copied terminal commands execute unexpected actions when pasted
- Website CAPTCHA asks you to paste clipboard into Run dialog or terminal
Tools you can use
Steps you can take
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading
MITRE ATT&CK
Clipboard Data technique (T1115) with 50+ documented malware samples
ESET WeLiveSecurity
First Android clipper on Google Play (Feb 2019)
Malwarebytes
Trojan.Clipper detection - clipboard theft targeting financial data
The Hacker News
Binance warning on rising clipper attacks (Sep 2024)
Kaspersky
Fake Tor Browser clipper stole $400K from 15K users across 52 countries (2023)
Trust Wallet
Consumer prevention guide with $560K single-attacker theft case