RAT (remote access trojan) that is deeply obfuscated and seeks to replace wallet addresses in clipboard with its own bad addresses.

just found out about this today, tho it seems to have been active since 2019/2020 (known as vipersoftx then, now as backendsoft).
you can read more about it here:

also a good breakdown of the modern iteration of this malware here:

  1. It would be great if you could provide any advice about how everyone can protect themselves best. Do you know if the popular anti-malware’s are able to detect and block this remote access trojan? From the fortinet article it mentions fortinet firewalls will block the RAT out of the box.



