Microsoft has recently shared insights into a cryptocurrency clipper malware campaign that has been affecting Windows users since February 2026. This malicious software utilizes Windows Script Host and ActiveX technology to execute a Tor proxy, which connects to a concealed command-and-control (C2) server. The Microsoft Defender Security Research Team highlighted that the clipper is designed to intercept cryptocurrency transactions by altering clipboard data, enabling attackers to redirect funds to their own wallets. The campaign primarily spreads through USB devices, where the LNK files are disguised to appear harmless. Once executed, the clipper operates silently in the background, making it difficult for users to detect its presence. Microsoft emphasizes the importance of maintaining updated security measures and being cautious with external devices to mitigate the risk of such threats. Users are advised to employ comprehensive security solutions and remain vigilant against suspicious activities.
Microsoft Unveils Windows Clipper Malware Campaign Utilizing USB LNK Worms
Microsoft has revealed a cryptocurrency clipper malware campaign targeting Windows users since early 2026, exploiting USB LNK worms.
