# GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)

> Gen Digital's H1 2026 Threat Report details two active, financially-motivated attack chains: a banking-fraud campaign (indicators point to GepyS) that moves from a compromised corporate mailbox through a JavaScript dropper, PowerShell stages, and an obfuscated shellcode loader to proxy and browser manipulation targeting users in Czechia, Slovakia, Poland, and Lithuania; and a separate Rust-compiled clipboard hijacker that monitors 21 blockchain types and silently swaps cryptocurrency wallet addresses before signing, resolving its C2 pointer via a Binance Smart Chain smart contract (EtherHiding).

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1934
- **ID:** TL-2026-1934
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Gen Digital's H1 2026 Threat Report (published 2026-07-15, "Attackers are Moving Closer to the Systems People Trust") and BleepingComputer's follow-up technical deep-dive ("Real emails, hijacked payments: Two H1 2026 attack chains," 2026-08-07) document two distinct, financially-motivated malware chains observed during H1 2026.

The first is a banking-fraud campaign whose available indicators point to the GepyS malware family. Attackers hijacked legitimate corporate email accounts and sent lures disguised as shipment notices, invoices, and scanned-document notifications from those already-compromised mailboxes — bypassing sender-reputation and SPF/DKIM-style trust signals because the sending accounts were genuine. Opening the attachment launches a JavaScript dropper, which pivots through multiple PowerShell staging steps before handing off to a 32-bit position-independent shellcode loader. The loader is deliberately hardened against static and dynamic analysis: it inserts MMX/SSE junk instructions and jumps into the middle of instructions to defeat linear disassembly, and decrypts its final payload using an LFSR-generated keystream followed by XOR. The end objective is not data theft but session interception: the malware modifies the victim's proxy configuration and installs a malicious browser add-on to position itself close to the victim's online banking session. Targeting concentrated on users in Czechia, Slovakia, Poland, and Lithuania. Gen also documented regional variants of the same delivery pattern: an Italian variant used fake invoice PDFs with Booking.com-themed lures, per-victim-obfuscated JavaScript hosted on Vercel, and PowerShell staging hosted on Blogspot to deliver the XWorm RAT; a Polish variant used a steganographically-concealed .NET loader to deliver the Remcos RAT.

The second chain is an unrelated but similarly financially-motivated cryptocurrency threat: a Rust-compiled, multi-coin clipboard hijacker ("clipper") that monitors clipboard content for wallet addresses across 21 blockchain types, including BTC, ETH, and LTC. When a victim copies a wallet address to paste into a wallet application or exchange, the malware silently substitutes an attacker-controlled address before the transaction is signed — the signed transaction itself is technically valid, but its destination was altered locally beforehand, so nothing about the signing flow looks wrong to the victim. The malware resolves its operational C2 pointer not from a conventional domain but from data stored in a Binance Smart Chain smart contract, a technique publicly referred to as EtherHiding. Because blockchain contract data is immutable, decentralized, and publicly readable, defenders have no domain to seize and no host to take down; the same public-readability that protects the attacker's infrastructure from takedown also makes the contract usable as an investigative pivot. Gen Digital's report and BleepingComputer's coverage provide no file hashes, C2 domains/IPs, malware sample filenames, CVE identifiers, or formal threat-actor attribution for either chain — only malware/tool family names (GepyS, XWorm, Remcos) and the described tradecraft.

EtherHiding-based, blockchain-resident C2 resolution is not unique to this campaign: Guardio Labs researchers Nati Tal and Oleg Zaytsev first detected the technique in the wild around August 2023 and publicly coined the term "EtherHiding" on 2023-10-16, describing its use by the ClearFake (FakeUpdates) campaign to abuse Binance Smart Chain contracts for payload-configuration delivery. Independent 2026 reporting (McAfee Labs, via Cyber Security News, 2026-05-19) describes an unrelated CountLoader-delivered cryptocurrency clipper using the same blockchain-based C2-resolution technique against a different, much larger victim population (primarily India, Indonesia, and the United States). Both are included here only as corroborating technique context — they document separate malware families and infrastructure, and neither is attributed to this GepyS/Rust-clipper threat.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1176 Software Extensions
- T1557 Adversary-in-the-Middle
- T1657 Financial Theft

## Sources

- [Real emails, hijacked payments: Two H1 2026 attack chains](https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/)
- [Threat Report H1 2026 - Gen Digital](https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026)
- [Gen Half-Year Threat Report: Attackers are Moving Closer to the Systems People Trust](https://www.prnewswire.com/news-releases/gen-half-year-threat-report-attackers-are-moving-closer-to-the-systems-people-trust-302826372.html)
- [Gen report reveals attackers are moving closer to the systems people trust](https://www.intelligentciso.com/2026/07/21/gen-report-reveals-attackers-are-moving-closer-to-the-systems-people-trust/)
- [Gen H1 2026 Threat Report: 114.2M Scams Blocked](https://www.stocktitan.net/news/GEN/gen-half-year-threat-report-attackers-are-moving-closer-to-the-4mxxrxyaxk68.html)
- [Gen Half-Year Threat Report: Attackers are Moving Closer to the Systems People Trust](https://www.barchart.com/story/news/3296019/gen-half-year-threat-report-attackers-are-moving-closer-to-the-systems-people-trust)
- [Security and Tech – Gen Half-Year Threat Report: Attackers are Moving Closer to Systems People Trust](https://livenews.co.nz/2026/07/17/security-and-tech-gen-half-year-threat-report-attackers-are-moving-closer-to-systems-people-trust/)
- [Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign (background on the blockchain-based C2 technique reused by the Rust clipboard hijacker)](https://thehackernews.com/2023/10/binances-smart-chain-exploited-in-new.html)
- [Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper (unrelated CountLoader-based campaign corroborating EtherHiding as an active 2026 clipboard-hijacking technique)](https://cybersecuritynews.com/malware-campaign-deliver-crypto-clipper/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1934
