the malware's main function seems to be to check the clipboard for crypto wallet addresses and then replace them with attacker addresses: Bitcoin (bc1): bc1qrzh7d0yy8c3arqxc23twkjujxxaxcm08uqh60v Litecoin (ltc1/L/M): LQ4B4aJqUH92BgtDseWxiCRn45Q8eHzTkH Ethereum (0x): 0x10A8B2e2790