Threat reportMalwareTL-2026-1934
GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)
GepyS Banking Malware and Rust Clipboard Hijacker (TL-2026-1934) is a high-severity malware campaign, first published 2026-08-07. It has no confirmed attribution, maps to 10 MITRE ATT&CK techniques (T1027, T1059, T1140), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-1934
- Threat ID
- TL-2026-1934
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target regions
- czechia, slovakia, poland, lithuania, italy
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in GepyS Banking Malware and Rust Clipboard Hijacker
Malware and tooling: GepyS, Remcos, Rust-compiled multi-coin clipboard hijacker, XWorm, EtherHiding (Binance Smart Chain smart-contract C2 resolution), Remcos
How GepyS Banking Malware and Rust Clipboard Hijacker works
Gen Digital's H1 2026 Threat Report details two active, financially-motivated attack chains: a banking-fraud campaign (indicators point to GepyS) that moves from a compromised corporate mailbox through a JavaScript dropper, PowerShell stages, and an obfuscated shellcode loader to proxy and browser manipulation targeting users in Czechia, Slovakia, Poland, and Lithuania; and a separate Rust-compiled clipboard hijacker that monitors 21 blockchain types and silently swaps cryptocurrency wallet addresses before signing, resolving its C2 pointer via a Binance Smart Chain smart contract (EtherHiding).
Gen Digital's H1 2026 Threat Report (published 2026-07-15, "Attackers are Moving Closer to the Systems People Trust") and BleepingComputer's follow-up technical deep-dive ("Real emails, hijacked payments: Two H1 2026 attack chains," 2026-08-07) document two distinct, financially-motivated malware chains observed during H1 2026.
The first is a banking-fraud campaign whose available indicators point to the GepyS malware family. Attackers hijacked legitimate corporate email accounts and sent lures disguised as shipment notices, invoices, and scanned-document notifications from those already-compromised mailboxes — bypassing sender-reputation and SPF/DKIM-style trust signals because the sending accounts were genuine. Opening the attachment launches a JavaScript dropper, which pivots through multiple PowerShell staging steps before handing off to a 32-bit position-independent shellcode loader. The loader is deliberately hardened against static and dynamic analysis: it inserts MMX/SSE junk instructions and jumps into the middle of instructions to defeat linear disassembly, and decrypts its final payload using an LFSR-generated keystream followed by XOR. The end objective is not data theft but session interception: the malware modifies the victim's proxy configuration and installs a malicious browser add-on to position itself close to the victim's online banking session. Targeting concentrated on users in Czechia, Slovakia, Poland, and Lithuania. Gen also documented regional variants of the same delivery pattern: an Italian variant used fake invoice PDFs with Booking.com-themed lures, per-victim-obfuscated JavaScript hosted on Vercel, and PowerShell staging hosted on Blogspot to deliver the XWorm RAT; a Polish variant used a steganographically-concealed .NET loader to deliver the Remcos RAT.
The second chain is an unrelated but similarly financially-motivated cryptocurrency threat: a Rust-compiled, multi-coin clipboard hijacker ("clipper") that monitors clipboard content for wallet addresses across 21 blockchain types, including BTC, ETH, and LTC. When a victim copies a wallet address to paste into a wallet application or exchange, the malware silently substitutes an attacker-controlled address before the transaction is signed — the signed transaction itself is technically valid, but its destination was altered locally beforehand, so nothing about the signing flow looks wrong to the victim. The malware resolves its operational C2 pointer not from a conventional domain but from data stored in a Binance Smart Chain smart contract, a technique publicly referred to as EtherHiding. Because blockchain contract data is immutable, decentralized, and publicly readable, defenders have no domain to seize and no host to take down; the same public-readability that protects the attacker's infrastructure from takedown also makes the contract usable as an investigative pivot. Gen Digital's report and BleepingComputer's coverage provide no file hashes, C2 domains/IPs, malware sample filenames, CVE identifiers, or formal threat-actor attribution for either chain — only malware/tool family names (GepyS, XWorm, Remcos) and the described tradecraft.
EtherHiding-based, blockchain-resident C2 resolution is not unique to this campaign: Guardio Labs researchers Nati Tal and Oleg Zaytsev first detected the technique in the wild around August 2023 and publicly coined the term "EtherHiding" on 2023-10-16, describing its use by the ClearFake (FakeUpdates) campaign to abuse Binance Smart Chain contracts for payload-configuration delivery. Independent 2026 reporting (McAfee Labs, via Cyber Security News, 2026-05-19) describes an unrelated CountLoader-delivered cryptocurrency clipper using the same blockchain-based C2-resolution technique against a different, much larger victim population (primarily India, Indonesia, and the United States). Both are included here only as corroborating technique context — they document separate malware families and infrastructure, and neither is attributed to this GepyS/Rust-clipper threat.
MITRE ATT&CK techniques used in TL-2026-1934
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Execution
T1059 Command and Scripting Interpreter
Persistence
Credential Access
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts
Impact
Remediation for GepyS Banking Malware and Rust Clipboard Hijacker
Immediate actions
- Block or sandbox JavaScript email attachments (.js/.jse) at the mail gateway, especially from external senders whose messages mimic shipment notices, invoices, or scanned-document notifications
- Alert on and restrict unsigned or unexpected browser-extension installations on endpoints, particularly on systems used for online banking
- Monitor for unauthorized proxy configuration changes (manual proxy or PAC URL) on endpoints, especially around banking-session activity
- Instruct users handling cryptocurrency transactions to verify the pasted destination wallet address character-by-character (or via an out-of-band channel) immediately before signing, since a copied address may have been silently substituted
Workarounds
- Restrict PowerShell execution policy and enable constrained language mode plus script-block logging to increase visibility into multi-stage PowerShell staging
- Restrict browser-extension installation to an enterprise allowlist to prevent the malicious add-on installs used for banking-session interception
Longer-term hardening
- Deploy EDR with behavioral detection for reflective/in-memory shellcode loading and PowerShell-to-shellcode execution chains
- Strengthen business-email-compromise detection (anomalous send behavior, impossible-travel logins, mailbox-rule monitoring) to reduce the impact of lures sent from already-compromised legitimate mailboxes
- Monitor endpoint outbound connections to blockchain RPC endpoints (e.g., Binance Smart Chain) as a potential indicator of EtherHiding-style C2 resolution
- Deploy clipboard-integrity or clipboard-hijacking detection tooling on systems used for cryptocurrency transactions
Timeline of GepyS Banking Malware and Rust Clipboard Hijacker
- Guardio Labs researchers Nati Tal and Oleg Zaytsev first detect the blockchain-smart-contract C2-resolution technique later named "EtherHiding" in the wild, in use by the ClearFake (FakeUpdates) campaign (per Guardio Labs' account that detection preceded their public disclosure by roughly two months) — the earliest documented precedent for the C2-resolution method later reused by the Rust clipboard hijacker in this report.
- Guardio Labs publicly coins and documents the term "EtherHiding," describing ClearFake's abuse of Binance Smart Chain smart contracts to host and serve payload-configuration/routing data with no domain or server for defenders to seize.
- Start of Gen Digital's H1 2026 telemetry window, within which both the GepyS-linked banking-fraud campaign and the Rust clipboard-hijacker campaign described in the report were observed.
- McAfee Labs reporting (via Cyber Security News) describes an unrelated CountLoader-delivered cryptocurrency clipper reusing EtherHiding-style Binance Smart Chain C2 resolution against a separate, much larger victim population (primarily India, Indonesia, and the United States) — corroborating that the technique was still active in the wild during the H1 2026 window covered by this report, though its indicators are not attributed to the GepyS/Rust-clipper threat documented here.
- Close of Gen Digital's H1 2026 telemetry window covering the observed banking-fraud and clipboard-hijacker activity.
- Gen Digital publishes its H1 2026 Threat Report, "Attackers are Moving Closer to the Systems People Trust," documenting the GepyS-linked banking chain and the Rust clipboard hijacker among other findings.
- Secondary press coverage of the Gen Digital H1 2026 Threat Report begins (LiveNews.co.nz), summarizing the report's trust-abuse findings.
- Further secondary press coverage of the Gen Digital H1 2026 Threat Report is published (Intelligent CISO), continuing to summarize the report's trust-abuse findings.
- BleepingComputer publishes "Real emails, hijacked payments: Two H1 2026 attack chains," a technical deep-dive detailing the GepyS-linked banking chain's shellcode-loader obfuscation, the Booking.com-themed Italian variant, and the Rust clipboard hijacker's EtherHiding-based C2 resolution.
Sources cited for GepyS Banking Malware and Rust Clipboard Hijacker
- Real emails, hijacked payments: Two H1 2026 attack chains
- Threat Report H1 2026 - Gen Digital
- Gen Half-Year Threat Report: Attackers are Moving Closer to the Systems People Trust
- Gen report reveals attackers are moving closer to the systems people trust
- Gen H1 2026 Threat Report: 114.2M Scams Blocked
- Gen Half-Year Threat Report: Attackers are Moving Closer to the Systems People Trust
- Security and Tech – Gen Half-Year Threat Report: Attackers are Moving Closer to Systems People Trust
- Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign (background on the blockchain-based C2 technique reused by the Rust clipboard hijacker)
- Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper (unrelated CountLoader-based campaign corroborating EtherHiding as an active 2026 clipboard-hijacking technique)
Detection coverage for TL-2026-1934
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1934 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.