Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
168
Global rank
119 infographic chevron month
Month rank
102 infographic chevron week
Week rank

Laplas Clipper is a crypto-stealing malware that gains unauthorized access to the victim’s clipboard and replaces their crypto addresses to trick them into sending their funds to the attacker’s wallet. This malicious program is offered for sale as a malware-as-a-service (MaaS) and often distributed with the help of loaders, including SmokeLoader.

Stealer
Type
ex-USSR
Origin
1 October, 2022
First seen
7 October, 2026
Last seen

How to analyze Laplas Clipper with ANY.RUN

Type
ex-USSR
Origin
1 October, 2022
First seen
7 October, 2026
Last seen

IOCs

IP addresses
2.21.239.138
150.171.28.10
18.244.18.38
150.171.109.107
2.21.110.200
20.42.73.27
2.21.239.135
2.16.168.54
178.208.87.49
150.171.22.17
23.194.190.151
150.171.28.12
2.21.110.208
150.171.27.10
150.171.27.11
2.16.204.160
135.232.92.137
57.153.246.3
2.21.20.144
40.126.31.69
Hashes
9bcc7d4b69bde322809dd9cb29281bbeaad79071fb1e4f792dde685ed93b782f
4f26fa1bef358966c4574981e04490b3cd30b4c48f74e56f25b385d31a3e469a
acfd3cd36e0dfcf1dcb67c7f31f2a5b9ba0815528a0c604d4330dfaa9e683e51
2413de0a5c66078987b1dd515fa6a90f7fabbc9071244d173210029b20fb5dac
6017552e8ce880024ae1a4f31030594857224073161d48f3057b9b1df0bca75f
e93fecbd5aaf599e92aac0249c0817b1f7aebde7f96d49570be87ccb6c2aa269
ad72b102fa4978d8d3ba19cc7796d7b59d7740341b70e389946b37a706f6bb19
dd6fd2f4fb85c49e530302b7d8f8eda9e2f490ea5456ab00372962c4466d81d9
f348482450f020f358afb1110050d7a143dc188b46d84956bc0e5e59d0429ef7
f9d94faebda62a4d9c48059ac39a83388db8cd135d70fa0036c8396ab907907b
9aa860cc629a8822f831826c96bc75f19197b8ad326dc70c2d33931f0d004337
0e57203d3d6679d2ab1c6fb84fdd3f4a2323eca3ce4a38248dc1be5028392a24
338955bdb88a3b402764c2085292b5b993ed64aa3e6b17b0e4cb25e1e22b776d
9f5d2c72044ad00416c3679a24a480102000745969e19db59e48c632b923caba
7b679812c49cc807100697b4b6b6a37923a85426c09486318c1b22b87baac586
34a390fcd7ba6ac40333b91c158578995b10f379d8dd261d379b80f1bcfbe0b6
fc9b69a5299d836a4a11a4a72f798348a57a2046b890f62211555670ad7f1124
9a58df7cc074bd1249dfa163b00cc9a196461b817b14f4d55964002b217411f3
d6a0360315e39015b73a527a2d096d0413b6555a5ae705556f095c7cbd28bc05
c046ffe6fbbd27df3bb31c8e272f1e25e40516a74e937d0270bf48de8fcf6add
Domains
assets.msn.com
api.msn.com
img-s-msn-com.akamaized.net
c.msn.com
ntp.msn.com
srtb.msn.com
r.msftstatic.com
c.bing.com
sb.scorecardresearch.com
th.bing.com
www.bing.com
r.bing.com
deff.nelreports.net
browser.events.data.msn.com
config.edge.skype.com
edge.microsoft.com
google.com
oneocsp.microsoft.com
login.live.com
activation-v2.sls.microsoft.com
URLs
https://edge.microsoft.com/serviceexperimentation/v2/
https://config.edge.skype.com/config/v1/edge/109.0.1518.115?clientid=-626569875466424637&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=17&mngd=0&installdate=1604373552&edu=0&bphint=0
https://ntp.msn.com/edge/ntp?locale=en&title=new%20tab&dsp=1&sp=bing&startpage=1&pc=u531
https://ntp.msn.com/bundles/v1/edgechromium/latest/ssr-extension.c8264382acf37d60.js
https://ntp.msn.com/bundles/v1/edgechromium/latest/web-worker.a415d192e77084ef.js
https://ntp.msn.com/edge/ntp?locale=en&title=new+tab&dsp=1&sp=bing&startpage=1&pc=u531&invalidaterender=marketchange
https://assets.msn.com/staticsb/statics/latest/mscmp/1.11/entry.js
https://assets.msn.com/staticsb/statics/latest/js/thirdparty/adsdk/mscmp/1.0.8/sdk.js
https://assets.msn.com/statics/icons/favicon_newtabpage.png
https://assets.msn.com/service/msn/user?apikey=1hyojsirvpenskk0hlnjf2092mhqiz7xfenifka9uc&activityid=6ac6415c-904c-40b6-9687-fd5bd16f86b2&ocid=pdp-peregrine&cm=en-gb&it=app&user=m-0e59fad159b062e305dded3a588d63b3&scn=app_anon&source=market-consolidation
https://assets.msn.com/staticsb/statics/latest/fluent-icons/arrow_up_24_regular.svg
https://assets.msn.com/service/news/feed/pages/weblayout?user=m-0e59fad159b062e305dded3a588d63b3&activityid=6ac6415c-904c-40b6-9687-fd5bd16f86b2&admindisabled=false&adoffsets=c1:-1,c2:-1,c3:-1,c4:-1&apikey=1hyojsirvpenskk0hlnjf2092mhqiz7xfenifka9uc&apptype=edgechromium&audiencemode=adult&backgroundimageisset=false&cm=en-gb&colstatus=c1:0,c2:0,c3:0,c4:0&column=c4&colwidth=300&contenttype=article,video,slideshow,webcontent&dhp=1&dprvalue=1&duotone=true&edgexpmask=512&inedgefeatures=false&it=app&l3v=2&layout=c4&memory=2&newsskip=0&newstop=48&ocid=anaheim-ntp-feeds&overlay=0&pgc=2083&pgname=default&pgtype=dhp&reverttimes=0&scn=app_anon&timeout=1000&vpsize=1280x589&wposchema=byregion
https://assets.msn.com/service/msn/user?apikey=1hyojsirvpenskk0hlnjf2092mhqiz7xfenifka9uc&activityid=6ac6415c-904c-40b6-9687-fd5bd16f86b2&ocid=pdp-peregrine&cm=en-gb&it=app&user=m-0e59fad159b062e305dded3a588d63b3&scn=app_anon&resetcohorts=true
https://assets.msn.com/staticsb/statics/latest/brand/new-msn-logo-color-black.svg
https://assets.msn.com/staticsb/statics/latest/icons-wc/icons/feedsettings.svg
https://assets.msn.com/bundles/v1/edgechromium/latest/vendors.edf37168d07d53ba.js
https://assets.msn.com/staticsb/statics/latest/mscmp/1.11/assets/en-gb.json
https://assets.msn.com/bundles/v1/edgechromium/latest/microsoft.d91c49a6070327ba.js
https://assets.msn.com/bundles/v1/edgechromium/latest/common.9cb4ff1154f3e40c.js
https://assets.msn.com/bundles/v1/edgechromium/latest/experience.03ea803bc714ea43.js
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

What is Laplas Clipper malware?

Laplas Clipper is a family of malware that possesses stealer capabilities. Specifically, it works by replacing victims’ cryptocurrency addresses with those of the attacker using the clipboard. As a result, users unknowingly end up sending their virtual coins and tokens to the wallet set up by the threat actor. First observed in late 2022, Laplas Clipper remains in operation to this day and gets regular updates.

Laplas is sold openly via Telegram channels and Darknet forums as a Malware-as-a-Service (MaaS). Any user interested in this malicious software can purchase a subscription, starting from one week ($49) and up to one year ($839). As part of the offering, operators receive a web panel that lets them control the entire process of replacing victims’ crypto addresses and get notifications about the malware’s activity.

Phishing campaigns are the most common method employed by threats actors for infecting victims’ computers with Laplas Clipper. Criminals often weaponize .pdf and office-suite format files to conduct multi-stage attacks. In many instances, the malware is being dropped by other malicious software, including SmokeLoader, which penetrates security mechanisms of computers and then downloads Laplas.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Technical details of the Laplas Clipper malicious software

Unlike other stealers, such as FormBook and Arkei, Laplas Clipper has a limited functionality, which focuses exclusively on hijacking victims’ cryptocurrency wallets. The capabilities of the malware include:

  • Generation of crypto addresses: Laplas Clipper can generate Bitcoin addresses for all three types: P2PKH (legacy), P2SH, and SegWit. It can also create addresses for ERC20, BEP20, and other tokens that use the 0x prefix, as well as Tron ones.
  • Choice of prefix or postfix generation: The malware allows users to choose whether to produce addresses with the prefix or postfix. This gives criminals more control over the appearance of illegitimate addresses.
  • Support for over 20 types of wallets: The software can replace addresses in most popular crypto wallets.
  • Web panel: Laplas Clipper can be managed through a web-based interface, letting the operator easily configure and use the clipper.
  • Autobuild functionality: Users of the malware can choose between three versions of the program: C++, Golang, and .NET 4.
  • Automatic balance check: Laplas Clipper can automatically check the balance of victims’ addresses.
  • Support for EXE, DLL extensions: Laplas Clipper can be built for both EXE and DLL extensions.

The malware creates addresses that are almost identical to the original ones. For example, the first three characters after the prefix of the attacker's address will be the same as those of the victim's address. This is often enough for an average user to mistakenly send their cryptocurrency to the wrong address. Apart from generating its own addresses, Laplas Clipper allows operators to use their custom ones.

As for the anti-analysis and anti-detection techniques, some versions of the malware are obfuscated with Babel, a popular obfuscator for .NET, which is capable of renaming symbols and encrypting strings. The malware is also equipped with debugger and virtualization evasion. Read the article “Analyzing a New .NET variant of LaplasClipper: retrieving the config” to learn more about the program’s code and collect its configuration.

Execution process of Laplas Clipper

Let’s load a sample of Laplas Clipper into ANY.RUN, an interactive malware sandbox, to expose its malicious activities and examine its behavior, as well as to gather up-to-date IOCs.

Laplas process tree Laplas Clipper's process tree

The task starts with the execution of a malicious file with the name "scdscxzccsacx_csharp_build_autorun.exe" located in the temporary folder. What's interesting is that this executable creates a scheduled task called "uAGRIUzbtd", which launches another executable named “svcupdater.exe.” This executable is located in the user's roaming folder stored inside the AppData directory (T1053.005). ANY.RUN shows that the "cmd" process was used to execute the "schtasks" process.

After one minute into the VM operation, the scheduled task starts the "svcupdater.exe" file. This indicates that the malware is attempting to establish persistence on the system by scheduling the execution of a file in the user's roaming folder. This behavior is commonly observed in malware that wants to maintain a presence on the system even after a reboot.

After that, the malware performs its main activity and begins to connect to C2 servers and collect information about the system. In this task, we can not only view the malware configuration by clicking the CFG icon next to the process or the MalConf button, but also download a dump of that process by clicking the DMP icon to perform additional analysis if needed.

Read a detailed analysis of Laplas Clipper in our blog.

Laplas process dump ANY.RUN lets you download a process dump of the analyzed sample

Distribution methods of the Laplas Clipper malware

Phishing emails are commonly used by criminals as the first step in multi-stage attacks that ultimately lead to LaplasClipper infection. These attackers often create emails that are misleading and deceive individuals into opening attachments that contain harmful files. For instance, attackers have been observed to pose as CoinPayments, a well-known cryptocurrency payment gateway, and request users to download a .zip folder. By executing the files from the archive, users inadvertently install Laplas Clipper on their systems.

Conclusion

Laplas is a newly developed malware that poses a serious threat to crypto holders worldwide. The malicious actors behind Laplas attacks have been successful in stealing substantial amounts of virtual coins. Therefore, individuals and companies that deal with cryptocurrencies must exercise extra caution when opening email attachments from unknown senders and suspicious files from untrusted sources. To ensure the safety of a document or link, it is recommended to use ANY.RUN. This platform provides conclusive verdicts on the malicious behavior of files and URLs and generates detailed reports, containing IOCs and configs for future detection of the threat.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More