BANKERCLIP
BANKERCLIP
BANKING TROJAN
ECRIME / LATAM
Threat IntelligenceMalwareSeptember 9, 202515 min read

BankerClip: Threat Intelligence Profile

Clipboard-hijacking banking malware

Scroll

BankerClip (also known as BankerClip) is a banking trojan active since 2018. Clipboard-hijacking banking malware. Key characteristics include: clipboard monitoring, crypto address swapping, banking credential theft.

Overview & Background

Clipboard-hijacking banking malware. First identified in 2018, this threat is attributed to eCrime / LATAM.

Threat Assessment

BankerClip remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this banking trojan.

Technical Analysis

BankerClip employs the following capabilities and techniques:

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentCommon delivery vector
ExecutionT1204.002 Malicious FileUser-triggered execution
PersistenceT1547.001 Registry Run KeysAutostart persistence
Defense EvasionT1027 Obfuscated FilesPayload obfuscation
C2T1071.001 Web ProtocolsHTTP/HTTPS C2

Detection & Defense

Defend Against BankerClip

Mjolnir Security provides detection and response capabilities against BankerClip and similar threats.

Threat DetectionIncident ResponseThreat HuntingMDR ServicesThreat Intelligence
  • Proactive Threat Hunting Hunt for BankerClip indicators and TTPs within your environment.
  • Threat Intelligence Monitor BankerClip campaigns and infrastructure changes.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: September 9, 2025