Check Point Research exposes a multi-platform malware campaign distributing Rust-based cryptocurrency clipboard hijackers for Windows and macOS. The threat actor disguises payloads as Solana sniper bots, Aviator Predictors, and crash-game tools, then uses Ghost Networks of fake accounts across GitHub, SourceForge, YouTube, and even VirusTotal to inflate stars, downloads, views, and 'safe' votes. The Windows variant embeds over 15,500 attacker-controlled wallet addresses covering Bitcoin, Ethereum, Monero, and many others; the macOS variant uses a similar design with one wallet per currency. Persistence is achieved via Windows Startup shortcuts and macOS LaunchAgent plists with a self-healing watchdog. Over 5,000 downloads were tracked on GitHub alone, with 44,000+ on SourceForge (many likely artificial). The campaign also abused news outlets and crypto forums for coordinated promotion, demonstrating how fake reputation manipulation across multiple platforms can lower victim suspicion and bypass reputation-based security controls.

19m read timeFrom research.checkpoint.com
Post cover image
Table of contents
Key PointsIntroductionPhishing PageGitHub & SourceForgeYouTube & AI UsageVirusTotal Upvotes ManipulationPromotion via News Sites & ForumsWindows VersionmacOS VersionConclusionIndicators of Compromise
224 Impressions