Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Diamotrix

91
Global rank
45 infographic chevron month
Month rank
79 infographic chevron week
Week rank
0
IOCs

Diamotrix is a stealthy cryptocurrency clipper malware that silently monitors the Windows clipboard, waiting for the moment a user copies a digital wallet address. Diamotrix replaces it with an attacker-controlled wallet, invisibly redirecting any resulting transaction. Because blockchain transfers are irreversible, victims rarely discover the theft until the funds are long gone.

Clipper
Type
Unknown
Origin
1 June, 2024
First seen
27 August, 2026
Last seen

How to analyze Diamotrix with ANY.RUN

Clipper
Type
Unknown
Origin
1 June, 2024
First seen
27 August, 2026
Last seen

IOCs

IP addresses
62.60.226.185
34.149.226.178
151.101.65.91
91.92.242.73
150.171.28.10
196.251.107.186
142.251.127.138
142.251.150.119
150.171.22.17
51.132.193.104
89.106.83.225
185.199.108.133
2.21.20.134
91.92.242.236
104.16.249.249
150.171.27.11
1.1.1.1
93.152.223.109
142.250.154.139
151.101.129.91
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
db037b650f36ff45da5df59bc07b0c5948f9e9b7b148ead4454ab84cb04fd0e2
50a670fb78ff2712aae2c16d9499e01c15fddf24e229330d02a69b0527a38092
2fca1f29b73dd5b4159fa1eb16e69276482f5224ba7d2219a547039129a51f0e
ec22297e0c7a6c6ed0262010a9a67b3a1d2e60a79763f83d366821456e848c4e
5c3a5b578ab9fe853ead7040bc161929ea4f6902073ba2b8bb84487622b98923
138c240382304f350383b02ed56c69103a9431c0544eb1ec5dcd7dec7a555dd9
0f404764d07a6ae2ef9e1e0e8eaac278b7d488d61cf1c084146f2f33b485f2ed
bcc0e6458249433e8cba6c58122b7c0efa9557cbc8fb5f9392eed5d2579fc70b
4d0bd3228ab4cc3e5159f4337be969ec7b7334e265c99b7633e3daf3c3fcfb62
517204ee436d08efc287abc97433c3bffcaf42ec6592a3009b9fd3b985ad772c
47576cae321c80e69c7f35205639680bf28010111e86e228ed191b084fac6b91
5b8d47451f847c1bde12caca3739ca29860553c0b6399ee990d51b26f9a69722
e2991a6f7a7a4d8d3c4c97947298fd5bacb3eaa2f898cee17f5e21a9861b9626
0aa66dff8a7ae570fee83a803f8f5391d9f0c9bd6311796592d9b6e8e36be6fc
a0415f14f5d72ad24e9c3a5c91517a0e3d22e1adbc3505c0c6e918b961f7a07d
c15ab85438728bf2c60d72b1a66af80e8b1ce3cf5eb08ba6421ff1b2f73acdf4
29d93dee7c01b2264778bc6b75f6ef76ea6ac53e9f4a334d83707229e7f482d2
b6cd5c6f2b54d89142679d599ed0a5dee6955a3b3f6b6673e46afe7a5a303cdc
6c15cb256b1c22170292589c6f589e64e164eb36ec7e84f0bd48149babb7c5fc
Domains
safeuploadz.com
www.gstatic.com
docs.google.com
login.live.com
ogads-pa.clients6.google.com
freedns.afraid.org
ratatwista.com
www.google.com
www.bing.com
fonts.gstatic.com
firefox.settings.services.mozilla.com
nexusrules.officeapps.live.com
update.googleapis.com
client.wns.windows.com
copilot.microsoft.com
accounts.google.com
detectportal.firefox.com
xxpro.dev
consent.youtube.com
ntp.msn.com
URLs
https://urlhaus.abuse.ch/downloads/text_online/
http://45.13.186.37/crypt/21-32/qw1.exe
https://tmcksa.com/bebe/bebeln.exe
http://193.104.58.65/binyu.exe
https://github.com/harveyjuansara/upd2352vhjh/raw/refs/heads/main/uninstall.exe
https://raw.githubusercontent.com/harveyjuansara/upd2352vhjh/refs/heads/main/uninstall.exe
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://github.com/harveyjuansara/upd2352vhjh/raw/refs/heads/main/minecraftpatch.exe
https://raw.githubusercontent.com/harveyjuansara/upd2352vhjh/refs/heads/main/minecraftpatch.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://196.251.107.186/clpr11.exe
http://196.251.107.186/asemkiic.exe
http://85.203.4.64/notepad.exe
http://193.221.200.26:5001/odens.exe
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
http://91.92.242.236/files-129312398/files/file_6bbb893ae4adfb7c.exe
http://196.251.107.186/clpmem.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2913
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8173
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10993
comments 0

How the Diamotrix Botnet Turns One "Copy-Paste" into a Six-Figure Loss

Key Takeaways

  1. Clipboard Hijacker: Diamotrix is a "clipper" malware that steals cryptocurrency by replacing wallet addresses in the clipboard.
  1. Botnet Architecture: It connects infected machines to a central botnet, allowing attackers to control theft on a massive scale
  1. Financial Sector Threat: It poses a direct and significant financial risk to any business or individual dealing in cryptocurrency.
  1. Loader Distribution: It often spreads via multi-stage loaders like "Optimal Dropper," which also installs other info-stealers
  1. Track IOCs with ANY.RUN’s Threat Intelligence Lookup to instantly investigate suspicious IPs, domains, or User-Agent strings associated with Diamotrix and visualize the full attack chain.

Diamotrix is often revealed by characteristic mutexes:

syncObjectName:"cleansystem_17582".

Diamotrix mutex search in TI Lookup Mutex search in TI Lookup exposes Diamotrix samples

  1. Security teams can detonate suspicious files in ANY.RUN’s Interactive Sandbox allows defenders to safely observe Diamotrix behavior and extract actionable indicators in real time.

View analysis

Diamotrix malware analysis in Interactive Sandbox Diamotrix replaces crypto wallet address in the clipboard

What is Diamotrix Malware?

Diamotrix is a type of infostealer malware specifically classified as a "clipper." It is designed to monitor the clipboard data of an infected Windows system. When a user copies what appears to be a cryptocurrency wallet address, the malware swiftly replaces it with an address controlled by the attacker. If the user then pastes the address to send a payment, the funds are inadvertently sent to the thief's wallet. Fortinet's FortiGuard Labs has identified it as a botnet, meaning infected machines can be centrally controlled to carry out this clipboard monitoring and theft on a large scale.

First observed in active campaigns around mid-2024 and formally identified by security researchers in September 2024, Diamotrix is distributed as a loader-delivered payload, frequently deployed alongside other commodity stealers such as Sniffthem, Rhadamanthys, and Stealc. It targets the Windows platform and has been confirmed by FortiGuard Labs, ANY.RUN sandbox analyses, and Red Piranha threat intelligence as a significant and growing threat to individuals, businesses, and organizations that handle cryptocurrency.

Unlike ransomware or wiper malware, Diamotrix does not announce its presence. It is a passive, persistent threat designed to remain undetected for as long as possible, silently waiting for the right moment to act. The malware establishes persistence in the Windows startup directory, communicates with a command-and-control (C2) server to retrieve fresh attacker wallet addresses, and then continuously monitors clipboard events in the background.

The malware is compiled as a 32-bit PE executable, disguised with metadata mimicking legitimate Windows system components (e.g., CompanyName: “Soft”, ProductName: “Software”, file version strings that mimic system files). It uses process injection techniques, injecting its code into Windows Explorer (explorer.exe) and other trusted system processes to evade endpoint detection. Communication with the C2 server is conducted over HTTP, fetching an updated wallet address pack (diamotrix[.]pack) and sending stolen transaction data via POST requests to the C2 API.

For the purposes of evasion, the clipper checks supported languages (possible sandbox/geo-evasion), reads machine GUID, checks proxy server settings, mimics Windows Services process names. Obfuscation is based upon control flow flattening and anti-analysis techniques confirmed in multi-stage deployments.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Diamotrix Threatens Businesses and Organizations

For individual users, Diamotrix represents direct and immediate financial loss — a single intercepted Bitcoin or Ethereum transfer can result in thousands of dollars disappearing silently. For businesses and organizations, the threat surface is substantially larger and more complex.

  • Direct Financial Loss: Any employee or automated system that handles cryptocurrency payments, treasury operations, payroll in digital assets, or DeFi transactions is a potential victim. Because transactions are irreversible on blockchain networks, there is no mechanism for recovery once funds are diverted.

  • Operational and Reputational Damage: The business may face contractual disputes, damaged supplier relationships, and reputational harm. If the victim is a financial institution, exchange, or crypto-native business, the reputational fallout can be catastrophic.

  • Multi-Payload Risk Amplification: Diamotrix is rarely deployed alone, it commonly is part of a multi-payload bundle that also includes sophisticated information stealers. A single infection event can simultaneously result in credential theft, browser data exfiltration, and cryptocurrency transaction hijacking.

  • Persistence and Lateral Threat Potential: If initial triage misses the persistence mechanism, the malware will resume activity after remediation efforts, allowing attackers to continue extracting value indefinitely.

Victimology: Vulnerable Industries and Sectors

While any individual or entity using cryptocurrency is a potential target, specific sectors are at higher risk due to the nature of their transactions:

  • Cryptocurrency Exchanges and Fintech: Employees with access to hot wallets or large transaction capabilities are prime targets.

  • Real Estate and Legal Firms: These sectors increasingly handle large down payments or settlements in cryptocurrency.

  • Technology and SaaS Companies: Firms that accept cryptocurrency for payments are vulnerable.

  • High-Net-Worth Individuals: Executives and owners who personally manage crypto assets are attractive victims.

How Can Businesses Proactively Protect Against Diamotrix

ANY.RUN’s Threat Intelligence solutions empower SOCs and MSSPs to combat Diamotrix by providing instant access to detailed malware verdicts, IOCs (hashes, domains, URLs, behavior signatures), and interactive sandbox reports. Business protection is assured by:

  • Rapid hash/domain lookup for incident triage and alert validation.

  • Contextual enrichment of alerts with real-time ANY.RUN analyses.

  • Proactive hunting for Diamotrix indicators in environments.

  • Reduced false positives and faster response times.

  • Cost-effective threat visibility and risk management.

Diamotrix’s threat model relies on speed: the malware needs only a fraction of a second to replace a clipboard entry, and the resulting transaction is irreversible. This means that retrospective detection — finding the infection after a theft has occurred — is fundamentally insufficient. Threat Intelligence Feeds shift the defense posture from reactive to proactive:

  • Real-time C2 blocking: As new Diamotrix C2 IP addresses and domains are identified through live sandbox analyses, TI Feeds push these indicators to SIEMs, firewalls, and IDS/IPS platforms in near-real-time — blocking communication before wallets can be fetched or data exfiltrated.

  • Fresh, low-noise IOCs: Indicators in TI Feeds are extracted from real, confirmed-malicious sandbox sessions rather than third-party aggregation, dramatically reducing false positives that cause alert fatigue.

  • STIX/TAXII delivery: TI Feeds are delivered in industry-standard STIX format via TAXII, enabling plug-and-play integration with platforms including MISP, ThreatQ, Splunk, Microsoft Sentinel, and other SIEM/SOAR/TIP solutions — no custom development required.

TI Feeds benefits and integration TI Feeds benefits and integration options

How Diamotrix Gets in the System and Functions

Diamotrix primarily infects systems through:

  • Spear-Phishing Emails: Malicious attachments disguised as legitimate documents or executables trick users into launching the malware.

  • Loader Malware: It is often dropped by other malware, such as the "Optimal Dropper" or loaders associated with SVCStealer, which act as delivery vehicles for multiple payloads.

  • Malicious Downloads: It can be hidden in cracked software, fake updates, or payloads hosted on malicious domains (e.g., diamotrix[.]online, diamotrix[.]club).

Once installed, Diamotrix establishes persistence through two mechanisms observed in sandbox analyses:

  • Registry persistence: Writes a startup entry to HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ensuring the malware relaunches after every system reboot under a randomized GUID-based folder and file name (e.g., {2F33566DA0B91573532102}).

  • Startup directory: Copies autoupdater.exe to the user’s Roaming AppData directory and places an executable in the Windows Startup folder, disguised as a legitimate autoupdater process.

The use of randomized GUID-based directory and file names makes static signature detection substantially more difficult, as each deployment generates a unique file path.

Initial Execution and Process Injection

Upon execution, the primary Diamotrix binary (or its loader component) first performs environmental checks: it reads the computer name, checks supported languages, reads the machine GUID from the registry, and checks proxy server information. These checks serve dual purposes gathering victim system intelligence and detecting sandbox or analysis environments. If the environment passes these checks, execution proceeds.

The malware then spawns autoupdater.exe in the user’s AppData\Roaming directory (disguised as a legitimate auto-update process) and uses it as a persistence relay. It also drops a secondary component which performs additional system enumeration.

Code Injection into Trusted Processes

Diamotrix injects malicious code into two trusted Windows processes: svchost.exe (the Windows service host) and explorer.exe (Windows Explorer). Process injection into explorer.exe is particularly effective because explorer.exe is always running, operates at medium integrity level, and is rarely flagged as suspicious for making network connections. This injection ensures that the clipper operates persistently in the background.

C2 Communication and Wallet Retrieval

The injected code in explorer.exe initiates C2 communication via HTTP GET request to retrieve the attacker’s current wallet address pack (diamotrix.pack). This design is significant: rather than hardcoding a single wallet address, Diamotrix fetches addresses dynamically, allowing operators to rotate their wallets to evade blockchain-based tracking. The C2 infrastructure communicates over standard HTTP port 80, blending with legitimate web traffic.

Clipboard Monitoring and Address Substitution

With the attacker’s wallet addresses loaded, Diamotrix’s core function begins: continuous monitoring of the Windows clipboard. The malware uses regex-based pattern matching (crypto-regex) to identify valid cryptocurrency wallet addresses as they are copied by the user. Major cryptocurrencies are targeted, including but not limited to Bitcoin (BTC), Ethereum (ETH), and likely others based on the regex library used. When a match is detected, the malware silently replaces the clipboard content with the attacker’s wallet address.

Data Exfiltration

Beyond wallet substitution, Diamotrix exfiltrates transaction data and victim information via HTTP POST requests to the C2 API endpoint (api[.]php). This telemetry allows the attacker to monitor which victims are actively making cryptocurrency transactions, the amounts involved, and the success rate of the wallet substitution.

Sandbox Analysis of Diamotrix Sample

The key stages of Diamotrix attack chain are visible in ANY.RUN’s Interactive Sandbox safe detonations:

View analysis

Diamotrix sandbox analysis Diamotrix sample in the Interactive Sandbox

Upon launching the malicious file, Diamotrix injects its code into the legitimate system process explorer.exe.

Diamotrix injected legal Windows process Diamotrix injected legal Windows process

To ensure persistence, the malware creates its own copy named System.exe in the directory %AppData%\Roaming\2F33566DA0B91573532102, and then adds a corresponding entry to the registry's autorun section.

Diamotrix secures persistence Diamotrix secures persistence

The core functionality of Diamotrix as a crypto clipper is entirely based on monitoring and modifying the clipboard. The malware continuously tracks the clipboard contents in real time and, upon detecting a cryptocurrency wallet address, instantly replaces it with an address controlled by the attacker.

We can observe this behavior during an analysis due to the interactivity functions of ANY.RUN’s Sandbox. A legitimate Bitcoin address bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq was copied to the clipboard. Immediately afterward, Diamotrix substituted it with an attacker-controlled address. Repeated tests involving the copying of cryptocurrency addresses confirmed replacement in every case.

Diamotrix replaces Bitcoin address in the clipboard Diamotrix replaces Bitcoin address copied to the clipboard

Gathering Threat Intelligence on Diamotrix Malware

ANY.RUN's Threat Intelligence Lookup provides critical capabilities for detecting, investigating, and responding to Diamotrix threats:

Rapid IOC Validation and Enrichment

SOC analysts can query TI Lookup to instantly determine if an indicator is associated with known Diamotrix campaigns. The service provides contextual information including malware family classification, campaign attribution, and related artifacts - turning isolated indicators into actionable intelligence within seconds.

Deep Behavioral Analysis Access

TI Lookup gathers direct links to interactive sandbox sessions where Diamotrix was analyzed. Analysts can observe the complete execution chain. Start exploring with the threat name lookup:

threatName:"diamotrix".

Diamotrix sandbox analyses Fresh Diamotrix sandbox analyses found via TI Lookup

YARA Rule Development and Testing

TI Lookup's integrated YARA Search allows security teams to scan ANY.RUN's threat intelligence database with custom detection rules. Teams can develop YARA rules targeting Diamotrix unique characteristics like mutex names and immediately test them against millions of analyzed samples to validate effectiveness and minimize false positives.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Diamotrix represents a shift towards highly targeted, financially motivated cybercrime. By focusing on the simple act of "copy-paste," it exploits a moment of user trust to divert funds. Its distribution through sophisticated loader campaigns and its operation as a botnet make it a persistent threat. Defeating it requires a combination of user education, robust endpoint monitoring, and, most critically, access to real-time threat intelligence that can track its evolving infrastructure and behavioral patterns.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
Tykit screenshot
Tykit
tykit
Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More