Friday, 19 June 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 19 June 2026 at 05:21

Microsoft discovers new self-propagating malware that steals cryptocurrency

Microsoft has uncovered a new worm named Crypto Clipper that spreads via USB drives, monitors clipboard content for crypto wallet addresses and seed phrases, and exfiltrates data through Tor.

Foto: Ars Technica

New malware targets cryptocurrency credentials

Microsoft announced it has detected a new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials. Dubbed Crypto Clipper, the worm monitors the device's clipboard for patterns matching wallet addresses or seed phrases. When found, it captures five screenshots over a 10-second period. Both credentials and screenshots are then sent to attacker-controlled servers via the Tor network, using a SOCKS5 proxy.

Lightweight backdoor

Microsoft noted that this malware is notable for not relying on a traditional installer or IP-based command-and-control infrastructure. Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.

USB-based propagation

Microsoft observed Crypto Clipper spreading through .lnk files on USB drives. These files contain executable code. When an infected USB drive is connected to a device, the code checks if the malware is already installed. If not, it downloads the malware via the Tor proxy. To conceal its presence, the malware scans the USB drive and renames the .lnk files with similar names.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category