The long road to your crypto: ClipBanker and its marathon infection chain

2026-04-09T20:51:57Zbb63d62ad17c393103f1f4cfd0ebbb44b7579ec625668fb69862eb52ff252093
BeatBankerCVE-2023-32434CVE-2023-38606CorunaCrystalXGoPixHorabotLiteLLMMaaSPAC-filesRATbanking-trojanclipbankerclipboard-hijackcryptocurrency-fraudexploit-kitfinancial-malwareinfostealerios-exploitkernel-exploitmalvertisingmalwarememory-onlysupply-chain-attackvulnerabilities-report

What happened

Kaspersky Securelist feed highlights a surge in financially motivated malware and high-risk supply-chain/exploit activity. Notable items: a trojanized Proxifier installer delivering ClipBanker that hijacks cryptocurrency clipboard contents; CrystalX RAT offered as MaaS with spyware, stealers and prankware; a LiteLLM supply‑chain compromise affecting AI gateways; the Coruna exploit framework (updated Operation Triangulation) using iPhone kernel exploits CVE-2023-32434 and CVE-2023-38606; and multiple banking/infostealer campaigns (GoPix, BeatBanker) along with a Horabot campaign and a Q4‑2025漏洞

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
bb63d62ad17c393103f1f4cfd0ebbb44b7579ec625668fb69862eb52ff252093
Enrichment time
2026-04-09T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The long road to your crypto: ClipBanker and its marathon infection chain · Baitaphish