Netskope Threat Labs

ClipBanker

ATP Sandbox Adv. HeuristicsAVNetskope IPS

ClipBanker is an infostealer that steals banking information among other data and typically spreads through phishing emails, malicious downloads, and social media links. It monitors clipboard activity, and some variants replace copied cryptocurrency wallet addresses with criminal controlled ones, redirecting payments to criminal accounts. Its credential theft focuses on banking and payment sites, and its operators monetize stolen data directly or resell it underground.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Infostealer.ClipBanker
ByteCode-MSIL.Spyware.ClipBanker
ByteCode-MSIL.Trojan.ClipBanker
DeepScan:Generic.BAT.ClipBanker.A.FFFFFFFE
Dropped:Trojan.ClipBanker.22
Dump:Generic.BAT.ClipBanker.A.FFFFFFFE
Dump:Generic.BAT.ClipBanker.A.FFFFFFFE:283ED
Email-MIME.Infostealer.ClipBanker
Gen:Variant.ClipBanker.216
Gen:Variant.ClipBanker.308