Kaspersky Flags Crypto-Stealing Malware Hidden in Fake Microsoft Office Add-Ins
Sujha has been recognised as 🟣 Women In Crypto 2024 🟣 by BeInCrypto for her leadership in crypto journalism.
- Stablecoin Inflows Have Doubled to $98B Amid Selling Pressure – Report
- Bitcoin Miner MARA Moves 1,318 BTC in 10 Hours, Traders Wary of Forced Miner Selling
- Bitwise Files S-1 With SEC to Launch Uniswap-Focused ETF, UNI Token Slumps 16%
- Bhutan Quietly Sells Over $22M in Bitcoin, Triggers Speculation Over Possible Sell-Offs
- Crypto Firms Propose Concessions to Banks as Stablecoin Disputes Stall Key Crypto Bill – Report

Cybersecurity firm Kaspersky has flagged a new sophisticated malware that steals crypto using fake Microsoft Office add-ins. These legit-looking extensions are uploaded to SourceForge, a website hosting platform, with descriptions copied from the legitimate GitHub project.
Per the malware description posted on Tuesday, appears with the SourceForge domain name and web hosting. “Pages like that are well-indexed by search engines and appear in their search results,” Kaspersky cybersecurity experts wrote.
Dubbed “officepackage,” the extension displays a list of office applications complete with version numbers and “Download” buttons.
Fake Downloads are Smaller in Size, Raises “Red Flags”
Kaspersky noted that the downloads are roughly seven-megabyte in size. “This raises some red flags, as office applications are never that small, even when compressed.”
The download pages takes victims to another page with a download button, containing a password-protected archive. However, the zip file after downloading the software exceeds 700 megabytes.
Attackers use the pumping technique to inflate the file size to look legit by appending junk data, Kaspersky flagged.
“As users seek ways to download applications outside official sources, attackers offer their own,” the report said. “They keep looking for new ways to make their websites look legit.”
⚠️ Cybersecurity firm @Kaspersky has issued a warning about a widespread malware campaign targeting users on @GitHub. #Kaspersky #GitHubhttps://t.co/TJg8BmgHiV
— Cryptonews.com (@cryptonews) February 26, 2025
Kaspersky Finds ‘ClipBanker’ Malware
The firm highlighted that the campaign injects the ClipBanker trojan through SourceForge. “ClipBanker is a malware family that replaces cryptocurrency wallet addresses in the clipboard with the attackers’ own,” it explained.
Crypto wallet users usually copy addresses rather than typing them. With the ClipBanker malware, the victim’s money will end up somewhere entirely unexpected.
Further, attackers could also sell system access to more dangerous actors apart from stealing cryptos.
“We advise users against downloading software from untrusted sources. If you are unable to obtain some software from official sources for any reason, remember that seeking alternative download options always carries higher security risks,” Kaspersky warned.
- Crypto Price Prediction Today 6 February – XRP, Dogecoin, Shiba Inu
- Best Crypto to Buy Now February 6 – XRP, Solana, Bitcoin
- Solana Price Prediction: $80 SOL Looks Scary – But Smart Money Just Signaled This Might Be the Bottom
- China’s DeepSeek AI Predicts the Price of XRP, Solana and Bitcoin By the End of 2026
- XRP Price Prediction: Key Ledger Upgrade Quietly Activated – Why This Could Be the Most Bullish Signal Yet
About Us
2M+
250+
8
70
Market Overview
- 7d
- 1m
- 1y
- Crypto Price Prediction Today 6 February – XRP, Dogecoin, Shiba Inu
- Best Crypto to Buy Now February 6 – XRP, Solana, Bitcoin
- Solana Price Prediction: $80 SOL Looks Scary – But Smart Money Just Signaled This Might Be the Bottom
- China’s DeepSeek AI Predicts the Price of XRP, Solana and Bitcoin By the End of 2026
- XRP Price Prediction: Key Ledger Upgrade Quietly Activated – Why This Could Be the Most Bullish Signal Yet
More Articles
Get dialed in every Tuesday & Friday with quick updates on the world of crypto