TwizAdmin -- Multi-Stage Crypto Clipper, Infostealer & Ransomware Operation
Reported 22 Apr 2026 by otx · Severity: medium
A sophisticated multi-stage malware operation was identified through an exposed C2 panel at 103.241.66[.]238:1337, combining cryptocurrency clipboard hijacking across eight chains, BIP-39 seed phrase theft, browser credential exfiltration, ransomware module (crpx0), and Java RAT