How to Remove Clipboard-Stealing Spyware Step by Step
Clipboard spyware is a quiet, dangerous category of malware that monitors what you copy — wallet addresses, BSB numbers, passwords, recovery phrases — and ships the data to a remote attacker. On Australian systems, the common outcome is an address-swap scam that redirects a crypto transfer or invoice payment to a fraudster's wallet, often before the sender in Sydney or Melbourne realises something is wrong.
This guide walks through isolating the device, removing the threat on Windows and macOS, and verifying the cleanup afterwards. It also covers recovery if files were encrypted alongside the clipboard theft, and the habits that make a repeat attack less likely.
Small businesses in Brisbane and Perth routinely paste BSB and account numbers into online banking forms, and clipboard-stealing code can swap those digits invisibly. Even share-house deposits in Adelaide have been drained this way. Treat anything copied on an untrusted machine as potentially exposed.
Speed matters. The longer the spyware runs, the more clipboard data it captures. Disconnect, identify, remove, and verify in that order. If a financial loss has already occurred, contact your bank, the Australian Cyber Security Centre, and Scamwatch before attempting recovery.
What clipboard spyware actually does
This malware hooks into the operating system's clipboard APIs and reads anything you copy within milliseconds. On Windows it often injects code into explorer.exe; on macOS it tends to live inside LaunchAgents. The stolen strings are forwarded to a command server, then sold in bulk or used directly for address substitution.
Attackers prefer the technique because victims do not notice a missing wallet digit until the transaction is irreversible. By the time a Brisbane user realises funds went to the wrong address, the coins are already being mixed through a tumbler.
Recognising the warning signs
Clipboard-stealing code rarely produces a single dramatic symptom. Crypto transactions arrive at the wrong wallet, BSB transfers return as "account not found", and pasted text sometimes carries trailing spaces you did not type. Battery drain on a MacBook or sudden fan noise on a Windows laptop can hint at background exfiltration.
Outbound traffic to unfamiliar IPs visible in your Telstra or Optus router logs is another strong indicator. If your wallet software warns that the recipient address has been flagged, treat it as confirmation that your clipboard is being intercepted.
Isolating the device before cleanup
Pull the Ethernet cable, disable Wi-Fi, and unplug USB drives before any removal work. This stops the spyware from receiving new commands, uploading more clipboard data, or downloading secondary payloads, and limits collateral damage if the same infection later tries to encrypt files.
| Indicator |
Likely stage |
Recommended action |
| Unknown process running as a service |
Active clipboard hooking |
Kill the process, block executable in firewall |
| Paste action adds extra characters |
Tampering layer present |
Boot into Safe Mode before manual removal |
| Browser home page changed |
Bundled adware |
Reset browser, run a second opinion scan |
| Wallet flags recipient address |
Confirmed address-swap |
Move funds to a freshly generated wallet now |
For users who already see encrypted files alongside the clipboard theft, the EaseUS recovery guide walks through restoring data after a ransomware event.
Removing the threat from a Windows PC
Boot into Safe Mode with Networking disabled by holding Shift while choosing Restart. From there, open Task Manager and end any unfamiliar processes, especially those that mimic system names such as svchost.exe but live inside AppData or Temp folders.
Run a reputable anti-malware scanner in full mode, review the quarantine list manually, and check registry run keys under HKCU and HKLM, scheduled tasks, and the Startup folder. Delete anything pointing to files you cannot verify, and finish with a second opinion scan from a different vendor.
Cleaning a macOS system
Restart into Recovery Mode with Command-R, confirm System Integrity Protection is on, then boot normally. Open Activity Monitor and sort by network usage to spot anything unusual. Inspect LaunchAgents and LaunchDaemons inside both the system Library and your user Library for recently modified plist files.
Remove suspicious plists along with their binaries, reset your browsers, and audit any software installed outside the Mac App Store. Cracked apps downloaded through torrent sites are a frequent carrier of clipboard code on macOS. Finish with a Mac-specific scanner.
Confirming the cleanup and recovering tampered data
After removal, restart normally and observe the clipboard for several hours. Copy a wallet address and verify it matches exactly, with no trailing characters or substitutions. Watch the network monitor for rogue outbound connections on ports 443 or 8080.
If files were encrypted alongside the clipboard theft, follow a structured recovery process such as the one in removing LockBit without a decryptor to maximise the chance of restoring data without paying a ransom.
Habits that keep clipboard-grabbing malware away
Treat your clipboard the way you treat your password manager: assume anything copied is potentially observable, particularly on shared or older hardware. Defensive habits also extend to recovery, since storing seed phrases offline means a single clipboard interception cannot drain an entire wallet.
The habits below make clipboard theft meaningfully harder for attackers and reduce the blast radius if a compromise does happen.
- Verify wallet addresses and BSB numbers by comparing the first and last four characters before confirming any transfer.
- Keep your operating system, browser, and wallet extensions fully patched.
- Avoid cracked software, unverified browser extensions, and "crypto tools" promoted through Discord or Telegram.
- Store long-term recovery phrases offline on paper or metal, never on an internet-connected device.
- Run a real-time anti-malware product with behavioural monitoring rather than signature-only detection.
- Use a hardware wallet for any meaningful holdings instead of relying on hot wallets.
- Read the site disclaimer before applying any third-party recovery tool to sensitive data.