Microsoft Identifies New Lightweight Malware Targeting Cryptocurrency

A new self-replicating malware has been discovered by Microsoft, designed to steal cryptocurrency credentials through USB drives.

3 min readSecurity

Microsoft has recently uncovered a novel form of self-replicating malware that infiltrates systems via USB drives, specifically targeting cryptocurrency credentials. This malware, dubbed Crypto Clipper, actively monitors clipboard contents for specific patterns that resemble cryptocurrency wallet addresses or seed phrases. Upon detection, it captures a series of five screenshots within a span of ten seconds. The stolen credentials and screenshots are then transmitted to servers controlled by the attackers using the Tor network, which anonymizes the data transfer by routing it through multiple nodes, thereby obscuring both the sender's and receiver's IP addresses. The malware establishes a connection to Tor through a SOCKS5 proxy, facilitating the traffic's journey to its destination. Microsoft highlighted the significance of this malware, noting that it operates without relying on traditional installation methods or visible command-and-control infrastructure. Instead, it utilizes a portable Tor client, effectively merging data theft with remote code execution, transforming a financially motivated thief into a stealthy backdoor.

Security