Feeds.4Sysops
New Crypto Clipper Malware Uses USB and Tor for Stealthy Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has identified a new cryptocurrency-stealing malware named Crypto Clipper, active since February 2026. This malware spreads primarily through malicious Windows shortcut files (.lnk) on USB drives, targeting Windows users. It employs worm-like behavior, enabling it to propagate itself to other USB devices. The malware monitors clipboard contents for cryptocurrency wallet addresses and can replace them with those controlled by the attacker. Additionally, it captures sensitive information such as seed phrases and private keys, and it can take screenshots of the victim's screen. Communication with its command-and-control server is conducted over the Tor network, making detection difficult. Microsoft recommends focusing on behavioral detection rather than relying solely on traditional signature-based methods. Security teams are advised to monitor for unusual script activity and connections to localhost:9050, which indicates Tor usage. The malware has been classified as Trojan:Win32/CryptoBandits.A.
Key Points: • Crypto Clipper malware spreads via USB drives using malicious .lnk files. • It monitors clipboard data for cryptocurrency addresses and steals sensitive information. • The malware uses Tor for covert communication, complicating detection efforts.