Malicious Office Add-ins Target Users with Crypto Miners and Wallet-Stealing Trojans

Kaspersky researchers have discovered a malware distribution scheme using Sourceforge, where attackers created a fake “officepackage” project offering Microsoft Office add-ins.
Users are redirected to a deceptive site and tricked into downloading an archive containing a Windows Installer file. Once executed, the file launches a chain of infections, deploying a cryptocurrency miner and the Clipbanker Trojan. Which swaps clipboard cryptocurrency wallet addresses with those of the attackers.
The attack has primarily targeted Russian-speaking users, with over 4,600 affected in a few months.
Clever Robot News Desk 10th April 2025