>> (p.1)
    Author Topic: PSA: Bitcoin Address Clipboard Malware  (Read 206 times)
    MisterBitconio (OP)
    Jr. Member
    *
    Offline Offline

    Activity: 65
    Merit: 4


    View Profile
    July 02, 2020, 04:43:31 PM
    Merited by o_e_l_e_o (2)
     #1

    I'm not sure if this is the correct place to put this (and apologies if this is old news), but I thought I'd share this so as to encourage anyone reading this to take the necessary safety measures when sending bitcoin.

    A friend of mine recently encountered a malware, which, upon copying a bitcoin address to your clipboard (with the purpose of pasting it in a wallet to issue a transaction) overrides that address and replaces it with the attacker's own bitcoin address. This is all done quietly, and the malware was not detected by the common antivirus software.

    Not to mention, if you are a person who uses VPS servers or connects to servers using Remote Desktop Connection or some other remote control software, this malware seems to be able to "go through" that software.
    Ex: If the VPS is infected and you have it opened using your RDC client, copying an address on your main machine will still allow the malware to change your clipboard (because of how RDC/RDP work).

    Always double check the first and last few letters of the bitcoin address you are sending money to, even if you just copy pasted it.
Page 1
Viewing Page: 1