Cyble A.I CyberSecurity Scoring
Cyble
Company Information
Website:https://cyble.com/
Employees number:250
Number of followers:83,862
NAICS:541514
Industry Type:Computer and Network Security
Homepage:cyble.com
Cyble Risk Score (AI oriented)
Between 600 and 649
CybleComputer and Network Security
Updated:
03/04/2026
03/04/2026
611/1000
Poor
Caa
Cyble Global Score (TPRM)
xxxx
CybleComputer and Network Security
Score locked

CyblePoor
Current Score
611Caa (POOR)
01000
3 incidents
-65 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
619
MAY 2026
614
APRIL 2026
614
MARCH 2026
629
Cyber Attack
05 Mar 2026 • Cyble
Cyble Research and Intelligence Labs: New Linux Threat ClipXDaemon Hijacks X11 Clipboard To Steal Crypto Transfers
ClipXDaemon Linux Malware Hijacks Crypto Wallet Addresses in X11 Sessions
609
LOW-20
CYB1773131064
New Linux Malware ClipXDaemon Hijacks Crypto Wallet Addresses in X11 Sessions
A recently discovered Linux malware, ClipXDaemon, is targeting cryptocurrency users by silently replacing copied wallet addresses with attacker-controlled ones during transactions. Identified by Cyble Research and Intelligence Labs in early February 2026 and detailed on March 5, 2026, the malware exploits the common practice of copy-pasting wallet addresses, redirecting funds to threat actors without the victim’s knowledge.
Unlike traditional malware, ClipXDaemon operates independently, eliminating the need for a command-and-control (C2) server. This makes it harder to detect, as it avoids network-based indicators of compromise. The malware is delivered via a loader using Bincrypter, an open-source shell-script encryption tool available on GitHub. While this technique was previously seen in ShadowHS campaigns, researchers found no direct link between the two threats only shared use of the same public tool.
ClipXDaemon focuses solely on clipboard hijacking within X11 sessions, a widely used Linux windowing system. It monitors clipboard activity and replaces cryptocurrency wallet addresses in real time. Since many users rely on copy-paste for transactions, a single unnoticed alteration can result in funds being sent to the attacker instead of the intended recipient.
The malware’s stealthy, self-contained design poses challenges for defenders, as traditional detection methods often rely on identifying suspicious outbound traffic or C2 communications. Its evolution reflects a broader trend in Linux malware toward targeted, profit-driven attacks that minimize detectable activity.
Security recommendations include transitioning from X11 to Wayland (which ClipXDaemon avoids), monitoring for unusual clipboard polling, and verifying wallet addresses manually before transactions. The threat underscores the persistent risk of clipboard hijacking in cryptocurrency operations, even on less commonly targeted Linux systems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
627
JANUARY 2026
735
Ransomware
13 Jan 2026 • Cyble
deVixor: New Android Banking Malware ‘DeVixor’ Adds Ransomware Capabilities
deVixor Android Banking Malware Campaign
625
CRITICAL-110
CYB1768350463
New Android Banking Malware "deVixor" Combines Ransomware with Credential Theft
Cyble researchers have uncovered deVixor, a sophisticated Android remote access trojan (RAT) targeting Iranian banking users with a blend of credential theft, surveillance, and ransomware capabilities. First detected in October 2023, the malware spreads via phishing websites impersonating automotive businesses, luring victims into downloading malicious APK files.
Originally focused on SMS harvesting, deVixor has rapidly evolved into a full-featured criminal platform. It now supports nearly 50 commands, including banking fraud, keylogging, ransomware deployment, and device surveillance. The malware leverages Firebase for command delivery and a Telegram-based bot infrastructure for scalable control, allowing attackers to evade detection while managing infections at scale.
Key features include:
- Credential theft: Harvests OTPs, banking credentials (via WebView-based JavaScript injection), and cryptocurrency exchange data.
- Surveillance: Captures keystrokes, screenshots, contacts, and device notifications while blocking uninstallation.
- Ransomware: Locks devices and demands TRON cryptocurrency payments, storing attack parameters in LockTouch.json to persist across reboots.
Cyble’s analysis of over 700 samples confirms deVixor is an actively maintained criminal service, with its Telegram channel suggesting broader future targeting. The malware’s modular design and persistent updates highlight the growing sophistication of Android banking threats, blending traditional fraud with disruptive ransomware tactics.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
735
NOVEMBER 2025
734
OCTOBER 2025
737
SEPTEMBER 2025
737
AUGUST 2025
737
JULY 2025
736
NOVEMBER 2020
754
Data Leak
01 Nov 2020 • Cyble
Cyble Inc.
Data Breach at Cyble E-commerce Firm
693
CRITICAL-61
CYB34529523
The Criminal Investigation Department (CID) and the Cyber Crime Police are searching for the hacker who gained access to private information belonging to the e-commerce firm Cyble and posted advertisements for the sale of the data on the dark web.
According to reports, the hacker sought payment from the business owner in order to remove the list.
The issue was discovered after Praveen B.S., the business's owner, discovered that his client list had been taken.
The data included details of all the customers who bought groceries and other products from his company’s online website, said a police officer.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Cyble ??
What was Cyble's A.I Rankiteo Cyber Score in May 2026 ??
What was Cyble's A.I Rankiteo Cyber Score in April 2026 ??
What was Cyble's A.I Rankiteo Cyber Score in March 2026 ??
What was Cyble's A.I Rankiteo Cyber Score in February 2026 ??
What was Cyble's A.I Rankiteo Cyber Score in January 2026 ??
What was Cyble's A.I Rankiteo Cyber Score in December 2025 ??
What was Cyble's A.I Rankiteo Cyber Score in November 2025 ??
What was Cyble's A.I Rankiteo Cyber Score in October 2025 ??
What was Cyble's A.I Rankiteo Cyber Score in September 2025 ??
What was Cyble's A.I Rankiteo Cyber Score in August 2025 ??
What was Cyble's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Cyble's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Cyble ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Cyble's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?