APT / THREAT GROUP

AnimateClipper

2
aliases

Intelligence Profile

According to Check Point Research, AnimateClipper is a cryptocurrency clipper that is delivered through a ClickFix-style phishing chain in which a built-in Windows utility runs a remote scripted page, leading to a bundled Python environment that executes embedded shellcode in memory to load the final payload without writing the unpacked binary to disk. The malware continuously monitors the clipboard for cryptocurrency wallet addresses, identifies the wallet format locally, and silently replaces the copied address with one of many embedded attacker-controlled wallets, enabling transaction hijacking across more than 20 blockchain ecosystems. It resolves its command-and-control server dynamically by querying a smart contract over a public blockchain JSON-RPC endpoint, then communicates over HTTPS for periodic check-ins and to report address-replacement activity. The embedded replacement wallets themselves are stored directly in the binary, and on-chain data indicates the operation has been active since at least mid-2025.

Threat Analysis

AnimateClipper is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning AnimateClipper

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

win.animate_clipperAnimateClipper

External Intelligence

Malpedia: win.animate_clipper

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.