Malware · 87 days ago
This campaign is harder to catch because it is not just stealing wallet data. The USB shortcut starts a worm that copies itself onto removable drives, and the stealer hides its command traffic behind a portable Tor client and local SOCKS5 proxy, which takes IP-based hunting off the table and leaves endpoint behavior as the better signal.
Microsoft says the campaign has been active since February 2026 and uses USB-delivered LNK files to launch the malware when a user opens what looks like a normal file. The malware then replaces document names with more shortcuts, keeps spreading to new USB media, steals clipboard wallet data and screenshots, and can also trigger remote code execution through C2 instructions, turning a clipper into a lightweight backdoor.
That makes network blocking less useful than before. The worm can keep reseeding machines through removable media, and the Tor-backed channel hides the server side from simple IP indicators, so defenders need to watch for the local process and USB behavior that shows the infection is still active.
4 sources covering this story
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution.
Microsoft discovers new lightweight backdoor that steals cryptocurrency
Crypto Clipper spreads over USB and communicates over Tor.
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
Microsoft reports a Windows clipper malware campaign using USB-delivered LNK files and Tor-based C2 since Feb 2026, stealing clipboard crypto data.
USB worm spreads crypto-stealing malware via Windows shortcut files
Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication.
Part of the PlainSec briefing for 2026-06-20