LIVE
Thailand Expands Probe Into Chinese-Led Crypto Mining NetworkBitcoin Falls Below $59,000 After U.S. PCE Inflation ReleaseSBI Holdings Acquires Bitbank for $288.6 Million in JapanCircle and Nomura Partner to Bring Instant FX Settlement to JapanRipple Partners With SBI Group to Launch Stablecoin in JapanHyperliquid X Launches Portfolio Margin in BetaAnthropic Pre-IPO Futures Drop After Coinbase DebutEthereum Foundation Cut Staff, Slashed Budget 40%: ReportTelegram Traders See 80% Chance of Bitcoin Falling Below $55,000Charles Schwab Bitcoin Trading Rollout: What We KnowThailand Expands Probe Into Chinese-Led Crypto Mining NetworkBitcoin Falls Below $59,000 After U.S. PCE Inflation ReleaseSBI Holdings Acquires Bitbank for $288.6 Million in JapanCircle and Nomura Partner to Bring Instant FX Settlement to JapanRipple Partners With SBI Group to Launch Stablecoin in JapanHyperliquid X Launches Portfolio Margin in BetaAnthropic Pre-IPO Futures Drop After Coinbase DebutEthereum Foundation Cut Staff, Slashed Budget 40%: ReportTelegram Traders See 80% Chance of Bitcoin Falling Below $55,000Charles Schwab Bitcoin Trading Rollout: What We Know
Homepage/News/Kaspersky Discovers Sourceforge Malware Targeting Crypto Users
NEWS

Kaspersky Discovers Sourceforge Malware Targeting Crypto Users

BY Solomon M.·1 MIN READ·APRIL 9, 2025

Kaspersky has identified a malware operation targeting cryptocurrency users, primarily Russian speakers, through fake Microsoft Office add-ins on SourceForge between January and March 2025.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
1Key sections mapped in this report
0Internal references connected to related coverage
2External source domains cited in the article
1 minEstimated time to read the full report
Key Takeaways:

  • ClipBanker malware targets crypto users via SourceForge.
  • Over 4,600 Russian-speaking users affected.
  • No major cryptocurrency market disruption reported.

kaspersky-discovers-sourceforge-malware-targeting-crypto-users
Kaspersky Discovers Sourceforge Malware Targeting Crypto Users

The incident highlights the vulnerability of cryptocurrency users to malware attacks, especially those relying on unofficial software downloads. Kaspersky Anti-Malware Research Team stated,

“Distributing malware disguised as pirated software is anything but new. As users seek ways to download applications outside official sources, attackers offer their own. They keep looking for new ways to make their websites look legit.”

Although individual crypto transactions are targeted, there has been no significant disruption in major cryptocurrencies.

Key players

Key players such as Kaspersky have identified the campaign facilitated by fake Microsoft Office add-ins. The attackers aim to hijack clipboard data and redirect cryptocurrency funds.

The ClipBanker malware was distributed through SourceForge, impacting over 4,600 users. It primarily affected individuals by substituting wallet addresses during transactions, which did not influence blockchain networks.

The financial impact remains undetermined, but losses are presumed significant given the number of affected users. No immediate regulations have been imposed, although security firms are alert to the threat.

Kaspersky’s warning emphasizes the importance of downloading from trusted sources. This attack represents a broader trend of leveraging platforms like SourceForge and Telegram for malware distribution. SourceForge Report from cybersecurity analysts confirmed this by stating that the campaign leveraged SourceForge, creating a deceptive project page resembling legitimate developer tools.

As crypto users face ongoing threats, increased attention to cybersecurity best practices is recommended. Vigilance against unofficial downloads and understanding new methods of legitimate-looking threats are crucial in maintaining security.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: kaspersky.com
  • External Source - Referenced domain: cointelegraph.com
  • Byline - Reported by Solomon M.
  • Coverage Desk - Primary editorial category: News
  • Media Asset - Featured image served from the WordPress media library
Kaspersky Discovers Sourceforge Malware Targeting Crypto Users | TheCCPress