Kaspersky Flags Crypto-Stealing Malware Hidden in Fake Microsoft Office Add-Ins

crypto wallet Malware
“ClipBanker is a malware family that replaces cryptocurrency wallet addresses in the clipboard with the attackers’ own."
Author
Last updated: 

Cybersecurity firm Kaspersky has flagged a new sophisticated malware that steals crypto using fake Microsoft Office add-ins. These legit-looking extensions are uploaded to SourceForge, a website hosting platform, with descriptions copied from the legitimate GitHub project.

Per the malware description posted on Tuesday, appears with the SourceForge domain name and web hosting. “Pages like that are well-indexed by search engines and appear in their search results,” Kaspersky cybersecurity experts wrote.

Dubbed “officepackage,” the extension displays a list of office applications complete with version numbers and “Download” buttons.

Fake Downloads are Smaller in Size, Raises “Red Flags”

Kaspersky noted that the downloads are roughly seven-megabyte in size. “This raises some red flags, as office applications are never that small, even when compressed.”

The download pages takes victims to another page with a download button, containing a password-protected archive. However, the zip file after downloading the software exceeds 700 megabytes.

Attackers use the pumping technique to inflate the file size to look legit by appending junk data, Kaspersky flagged.

“As users seek ways to download applications outside official sources, attackers offer their own,” the report said. “They keep looking for new ways to make their websites look legit.”

Kaspersky Finds ‘ClipBanker’ Malware

The firm highlighted that the campaign injects the ClipBanker trojan through SourceForge. “ClipBanker is a malware family that replaces cryptocurrency wallet addresses in the clipboard with the attackers’ own,” it explained.

Crypto wallet users usually copy addresses rather than typing them. With the ClipBanker malware, the victim’s money will end up somewhere entirely unexpected.

Further, attackers could also sell system access to more dangerous actors apart from stealing cryptos.

“We advise users against downloading software from untrusted sources. If you are unable to obtain some software from official sources for any reason, remember that seeking alternative download options always carries higher security risks,” Kaspersky warned.

In the Article
Bitcoin
BTC
$88,872
0.82 %
Ethereum
ETH
$3,026
1.57 %
XRP
XRP
$1.9164
0.49 %
Litecoin
LTC
$77.63
0.64 %
Cardano
ADA
$0.3671
0.32 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,140,400,758,589
1.73
Trending Crypto

More Articles

Altcoin News
Northern Data Sells Peak Mining to Tether-Linked Firms in Deal Worth Up to $200M
Amin Ayan
Amin Ayan
2025-12-22 06:29:17
Blockchain News
Hyperliquid Confirms $HYPE Shorting Address Linked to Ex-Employee Fired In 2024
Shalini Nagarajan
Shalini Nagarajan
2025-12-22 06:12:08
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors