BitCoin Clipper malware – malicious program designed to steal funds from cryptocurrency wallets

BitCoin Clipper malware is a type of computer virus that is spread by cybercriminals to steal Bitcoin, Dash, Monero, Ethereum, or Bytecoin from crypto-wallets. The malware does it by intercepting the copied clipboard information and secretly replacing it with criminals' wallet address. As a result, instead of performing a transaction to the intended recipient, victims transfer money directly to malicious actors.
Besides being able to steal cryptocurrency, BitCoin Clipper virus is capable of a variety of other malicious functions, since it is often distributed along with other malware, most commonly, Supreme botnet and Poullight info-stealer. Both of these infections are designed to steal sensitive user data and also send spam via the botnet, compromising more machines in the process. BitCoin Clipper virus is a dangerous infection that could result in monetary losses or even identity theft.
| Name | BitCoin Clipper virus |
| Type | Info-stealer, malware, Trojan |
| Infection means | Other malicious software, files downloaded from insecure or legitimate websites, email spam, etc. |
| Symptoms | Stealthy malware rarely shows infection symptoms, but some users might experience crashes, slowdowns, Blue Screens of Death errors, redirects to malicious websites, Application error, high computer resource usage, and other |
| Related | Gen:Variant.Razy, Trojan.Downloader, Ymacco Trojan, pPkvPAwhdu9dYJmd.exe, startwe.exe |
| Associated risks | Installation of other malware, loss of personal files, sensitive information theft, identity fraud, monetary losses |
| Removal | Download and install powerful anti-malware software, then perform a full system scan (in Safe Mode if required – we explain how below) |
| System fix | Malware can leave the computer vulnerable and compromised, even it is removed. In case you suffer from system crashes or similar stability issues, you can attempt Windows repair with tools such as FortectIntego |
There are several methods of how you could infect your computer with Bitcoin Stealer, although the most common means of infection is email spam. Since the infected hosts begin sending out malicious spam emails automatically, the infection rate can increase rapidly. Botnets were the causes of most dangerous computer infections worldwide, and are often spreading banking trojans or ransomware.
A sample of BitCoin Clipper virus, known as startwe.exe, was most likely downloaded from an insecure site that distributes pirated software. Most of the security applications track the installer under the following names:[1]
- Gen:Variant.Razy.613321
- Win32:RATX-gen [Trj]
- Trojan.Downloader.MSIL
- HEUR:Trojan-PSW.Win32.Generic
- Trojan:Win32/Ymacco.AAD4
- Trojan.Win32.Generic!BT, etc.
As evident, the malware is also named as a Trojan Downloader – a type of infection that can be used to download other malicious files and infect the machine further. Thus, if you infected your computer with a Bitcoin Stealer, there is a high chance that BitCoin Clipper malware removal is not the only infection that should be eliminated from the machine.
Once inside the system, the BitCoin Clipper virus performs a variety of changes on the machine to begin its malicious deeds. For example, it alters the Windows registry to be booted each time machine is launched, establishes background connection to a particular URL, deletes some files, launches new processes, etc.
As soon as Bitcoin Stealer has established all the needed connections and performed the needed system changes (note: some of these might be difficult to revert manually, so we recommend using FortectIntego as a quick solution to remediate Windows after the infection is terminated), it detects and steals information from Google Chrome, Mozilla Firefox, FileZilla, Discord, and other user accounts. However, this behavior is not visible to the host, and the infected users continue to use their computers as previously.

Since Bitcoin (or other currency) wallet address is a combination of alphanumeric characters that are difficult to type, they often copy and paste this information into the required field. This is where the BitCoin Clipper virus comes in – it secretly replaced the clipboard data with a crypto-wallet address of the attacker. Funds are then delivered to cybercriminals instead of the intended recipient.
Besides, BitCoin Clipper is also capable of a variety of other features, such as capturing the screen by taking screenshots, stealing all the typed in the information, downloading and installing other malicious files, updating itself, and much more. Thus, there is a great need to delete the infection as soon as possible.
However, since malware uses obfuscation and might sometimes stop security apps from detecting it in the first place, it might be difficult to remove BitCoin Clipper malware from the computer. Nonetheless, if you have issues with the process, you can access Safe Mode with Networking and perform a full scan from there.
Don't get tricked by malicious spam
Spam emails remain the leading cause of malware infections worldwide.[2] In many cases, malicious actors compile a “lazy” email that only includes a couple of words and an attachment or an embedded link. However, some phishing emails are extremely well done, so users might get easily tricked. This is why security researchers advise[3] always being vigilant when checking your Inbox or surfing the web.
Keep in mind that threat actors can use logos, formatting, buttons, and other attributes that do not belong to them. For example, the UPS or other delivery service is often used to trick users into opening malicious attachments. Besides, the attached files might be compressed and not seem like executables in the first place – you should never allow a macro function to run on your system, as it can execute malicious commands that would allow the attachment to download the payload of malware.
You should also be aware that outdated programs/operating systems, software crack downloads, unprotected Remote Desktop connections, and lack of adequate security software can also lead to infection of dangerous malware, so protect your machine properly and avoid visiting suspicious websites such as torrents.
Remove BitCoin Clipper virus from your system as soon as possible
As evident, BitCoin Clipper virus removal might sometimes be difficult due to multiple reasons – malware might attempt to disable or corrupt the installed security program or hide its presence for weeks or even months before it can be tracked. Therefore, if you are not sure whether your machine is infected with malware, make use of security software and perform a full system scan. In case your anti-malware is malfunctioning, you should attempt to download a different tool and perform a scan with it.

However, you should be able to remove BitCoin Clipper malware if you access Safe Mode with Networking – we explain below what should be done in order to access this mode. Since Windows boots with very few processes and drivers, malware becomes temporarily non-functional. This way, you should be able to perform a full system scan and delete the infection and all its components from your PC.
Was this guide helpful?
Be the first to comment