New lightweight self-propagating USB-delivered crypto-stealing malware discovered by Microsoft researchers – Crypto Clipper script-based stealer hunts vulnerable wallets


  • Microsoft Warns About “Crypto Clipper,” A Worm That Spreads Via Malicious .LNK Files On USB Drives
  • Malware maintains persistence, connects to Tor C2, enables remote code execution and steals encryption data from clipboard
  • It swaps wallet addresses, exfiltrates seed phrases/private keys and uploads screenshots to assess the target value

Microsoft is warning of an ongoing campaign targeting cryptocurrency owners with a clipboard-jacking worm.

In a new in-depth report published at the end of last week, Microsoft security researchers explained that they recently analyzed a thumb drive that contained seemingly normal documents (Word files, Excel spreadsheets). However, the documents were replaced with Windows shortcut files (.LNK), which actually launched a piece of malware called Crypto Clipper.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top