Financial Risk
XWorm Cryptocurrency Theft Risks
Clipboard monitoring, address replacement, browser-wallet exposure, and MetaMask-related session/data theft.
AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04
Some XWorm campaigns have used clipboard monitoring to identify and replace cryptocurrency addresses. Trellix documented such behavior in XWorm campaigns in 2023. Microsoft specifically identifies MetaMask hijacking among observed XWorm risks.
Clipboard hijacking concept
VICTIM COPIES WALLET ADDRESS
↓
MALWARE MONITORS CLIPBOARD
↓
ADDRESS MAY BE REPLACED
↓
USER PASTES ATTACKER ADDRESS
Defensive guidance
Always verify cryptocurrency addresses before confirming high-value transactions. Review browser-wallet and MetaMask exposure after any XWorm compromise.
