JoseCmanXD Rust Crypto Clipboard Hijacker ("silke"/"silkebin") Distributed via Fake Reputation Across GitHub, SourceForge, YouTube and VirusTotal — Threadlinqs Intelligence
As of 2026-06-17, JoseCmanXD Rust Crypto Clipboard Hijacker ("silke"/"silkebin") Distributed via Fake Reputation Across GitHub, SourceForge, YouTube and VirusTotal is a high-severity malware threat attributed to JoseCmanXD, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-0840 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: JoseCmanXD · FINANCIAL
A financially-motivated actor known as @JoseCmanXD distributes a cross-platform Rust clipboard hijacker (clipper) disguised as crypto trading bots and game predictors, building fake reputation through
Check Point Research disclosed (June 17, 2026) an active, financially-motivated campaign operated by an actor using the Telegram/WordPress handle @JoseCmanXD that distributes a cross-platform Rust-based clipboard hijacker (a 'clipper'). The malware is delivered under the guise of cryptocurrency trading tools and gambling 'predictor' applications — Solana/Pump.fun sniper bots, Aviator Predictor, crash-game predictors and DEX trading automation — targeting users seeking shortcuts and quick crypto profits.
On Windows, a simple .NET loader executes an embedded Rust binary located at src/config/silkebin.exe. The Rust clipper copies itself to %APPDATA%\silke\silke.exe and establishes persistence via a Startup-folder shortcut. It registers a clipboard listener (AddClipboardFormatListener) and continuously inspects clipboard contents with embedded regular expressions for more than a dozen cryptocurrency address formats — Bitcoin (Bech32, legacy P2PKH, P2SH), Ethereum/EVM, Litecoin, TRON, XRP, Cardano, Monero, Dogecoin, Bitcoin Cash, Bitcoin Gold, Stellar and Zcash. When a wallet address is detected it is replaced (via OpenClipboard/EmptyClipboard/SetClipboardData) with an attacker-controlled address. The Windows variant ships a large embedded wallet database of roughly 15,000+ attacker Bitcoin addresses (~5,000 each of Bech32, legacy and P2SH) plus ~500 Ethereum addresses and entries for 15+ additional currencies, chosen to closely resemble the victim's intended recipient.
On macOS, a loader runs unlocker.command which bypasses Gatekeeper by stripping the quarantine attribute with 'xattr -cr' before launching the lure application. The macOS Rust executable monitors the pasteboard for wallet-like strings and persists by writing a shell script to ~/launch.sh and installing a LaunchAgent property list at ~/Library/LaunchAgents/com.example..plist, causing launchd to silently re-execute the binary on every login. A 30-second watchdog loop continuously re-writes both files and re-clones the binary to survive removal. The macOS variant uses a single attacker wallet per currency rather than a large database.
The campaign's defining characteristic is large-scale reputation manipulation. A WordPress phishing site acts as the central hub linking to all tools. The actor operates at least six GitHub accounts (Decryptor-j, crash-predictor1, roblox-script1, hack-scripts, stake-mines and others) whose repositories carry inflated stars (e.g. 146 stars, 62 forks) and have accrued ~5,000+ downloads (1,250+ for the macOS Aviator Predictor). Multiple SourceForge projects show 44,485 downloads, of which ~37,460 originate from suspicious Android devices concentrated in Pakistan and India, indicating download-farm inflation. The YouTube channel uses AI-generated narration and shows view spikes and positive engagement driven by Ghost Accounts. On VirusTotal, sock-puppet accounts post benign community comments and cast 'harmless' votes to disguise clearly malicious samples. Coordinated 'news' advertisements promoting the tools were published simultaneously across multiple outlets on April 27, 2026.
The actor has been active on hacking forums since 2019 and in 2022 advertised a tool titled 'BLACKHAT | Bitcoin Stealer | Advanced Builder | Tutorial | Clipper [Address Changer] + Re-Fud method', with early Russian-language YouTube content later shifting to English for a global audience. Blockchain analysis shows the attacker wallets received multiple transactions yielding notable illicit gains, and wallets are rotated frequently — once a malicious transaction completes the used wallet is swapped for a fresh 'clean' one. The malware is updated every few weeks, indicating an ongoing, profitable operation. No CVE is involved; this is commodity malware leveraging social-engineering supply-chain abuse rather than a software vulnerability.
Target sectors: cryptocurrency, individuals, online-gambling, finance
Target regions: Global, Russia, Pakistan, India
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583.006, T1585.001, T1587.001, T1608.001, T1566.002, T1204.002, T1204.001, T1059.004, T1547.001