• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX GLOBAL
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

CryptoClippy Speaks Portuguese

by CXO Staff
April 7, 2023
in News

Additionally, Unit 42 research shows that the threat actors are using Google Ads and traffic distribution systems to redirect victims to malicious domains impersonating legitimate applications like WhatsApp

CryptoClippy Speaks Portuguese

Unit 42 recently discovered a malware campaign targeting Portuguese speakers, which aims to redirect cryptocurrency away from legitimate users’ wallets and into wallets controlled by threat actors instead. To do this, the campaign uses a type of malware known as a cryptocurrency clipper, which monitors the victim’s clipboard for signs that a cryptocurrency wallet address is being copied.

The malware, which we call CryptoClippy, seeks to replace the user’s actual wallet address with the threat actor’s, causing the user to inadvertently send cryptocurrency to the threat actor. Unit 42 Managed Threat Hunting found victims across manufacturing, IT services, and real estate industries, though they likely impacted the personal wallet addresses of someone using their work machine.

To deliver the malware to users’ computers, threat actors in this campaign used both Google Ads and traffic distribution systems (TDS) to redirect victims to malicious domains that are impersonating the legitimate WhatsApp Web application. They use this to ensure victims are real users, and also that they’re Portuguese speakers. For users who are sent to malicious domains, the threat attempts to trick them into downloading malicious files, including either .zip or .exe files, that lead to the final payload.

Palo Alto Networks customers receive protections against this campaign through Cortex XDR. The Advanced URL Filtering and DNS Security cloud-delivered security services for the Next-Generation Firewall identify domains associated with the CryptoClippy campaign as malicious.

To access the full report, please visit here

Additionally, Unit 42 research shows that the threat actors are using Google Ads and traffic distribution systems to redirect victims to malicious domains impersonating legitimate applications like WhatsApp.

Notable highlights from the report include:

  • The malware, which Unit 42 has deemed CryptoClippy, aims to redirect cryptocurrency funds away from legitimate users’ wallets and into wallets that belong to threat actors.
  • To date, the campaign is specifically targeting Portuguese speakers across Latin America.
  • A CryptoClippy infection begins with SEO poisoning; for example, when a victim searches for “WhatsApp Web,” the result leads them to a threat actor-controlled domain.
  • Threat actors then actively monitor a victim’s clipboard activity for Bitcoin transactions, ultimately taking their valid crypto wallet address and replacing it with one controlled by the threat actors.
  • Unit 42 Managed Threat Hunting found victims across manufacturing, IT services, and real estate industries, though they likely impacted the personal wallet addresses of someone using their work machine.
Tags: CryptoClippyfeatured4portugese
ShareTweet

Related Posts

BeyondTrust insights: What’s next for cybersecurity in 2026 and beyond
Business

BeyondTrust insights: What’s next for cybersecurity in 2026 and beyond

December 22, 2025

BeyondTrust has announced its top cybersecurity predictions for 2026 and beyond, identifying the trends that will redefine how organisations protect...

Kuwait Innovation Centre and Keeta launch Kee programme to support and empower local SMEs
Business

Kuwait Innovation Centre and Keeta launch Kee programme to support and empower local SMEs

December 22, 2025

Kuwait Innovation Centre (KIC) and Keeta announced the signing of a Memorandum of Understanding to launch the first edition of...

Discussion about this post

Latest Issue

BeyondTrust insights: What’s next for cybersecurity in 2026 and beyond

BeyondTrust insights: What’s next for cybersecurity in 2026 and beyond

December 22, 2025
From AI pilots to enterprise impact: DXC on closing the execution gap

From AI pilots to enterprise impact: DXC on closing the execution gap

December 22, 2025
Kuwait Innovation Centre and Keeta launch Kee programme to support and empower local SMEs

Kuwait Innovation Centre and Keeta launch Kee programme to support and empower local SMEs

December 22, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.