New lightweight, self-propagating USB-delivered cryptocurrency theft malware detected by Microsoft researchers: Crypto Clipper script-based thief searches for vulnerable wallets



  • Microsoft warns about “Crypto Clipper,” a worm that spreads via malicious .LNK files on USB drives
  • Malware maintains persistence, connects to Tor C2, allows remote code execution, and steals cryptographic data from clipboard
  • Exchange wallet addresses, extract seed phrases/private keys, and upload screenshots to evaluate target value.

Microsoft warns of an ongoing campaign targeting cryptocurrency owners with a clipboard-hijacking worm.

In a new in-depth report published late last week, Microsoft security researchers explained that they recently analyzed a USB stick containing seemingly normal documents (Word files, Excel spreadsheets). However, the documents were replaced by Windows Shortcut (.LNK) files that actually launched a malware called Crypto Clipper.

Leave a Comment

Your email address will not be published. Required fields are marked *