USB Worms Now Hide Behind Tor

This campaign is harder to catch because it is not just stealing wallet data. The USB shortcut starts a worm that copies itself onto removable drives, and the stealer hides its command traffic behind a portable Tor client and local SOCKS5 proxy, which takes IP-based hunting off the table and leaves endpoint behavior as the better signal. Microsoft says the campaign has been active since February 2026 and uses USB-delivered LNK files to launch the malware when a user opens what looks like a normal file. The malware then replaces document names with more shortcuts, keeps spreading to new USB media, steals clipboard wallet data and screenshots, and can also trigger remote code execution through C2 instructions, turning a clipper into a lightweight backdoor. That makes network blocking less useful than before. The worm can keep reseeding machines through removable media, and the Tor-backed channel hides the server side from simple IP indicators, so defenders need to watch for the local process and USB behavior that shows the infection is still active.

Part of the PlainSec briefing for 2026-06-20

Sources