AUTO-UPDATED

Crypto Clipper uses Tor and worm-like propagation for persistence and control

Microsoft Threat Intelligence has identified a sophisticated Windows-based cryptocurrency clipper malware, active since February 2026, that uses Tor-routed communications to steal digital assets and execute remote commands.

Key Points

  • The malware spreads via malicious .lnk shortcuts on USB drives, deploying a worm component for propagation and a stealer component for data harvesting.
  • It monitors the clipboard every 500 milliseconds to intercept cryptocurrency seed phrases, private keys, and wallet addresses for real-time substitution.
  • Attackers utilize a bundled Tor client and local SOCKS5 proxy on port 9050 to communicate with hidden-service command-and-control servers anonymously.
  • The threat includes remote code execution capabilities, allowing attackers to push arbitrary scripts to compromised systems via an EVAL command.
  • Microsoft Defender detects the threat as Trojan:Win32/CryptoBandits.A and identifies suspicious behaviors like unauthorized PowerShell screen captures and script-based data exfiltration.

Why it Matters

This campaign demonstrates how lightweight, script-based malware can evolve into a persistent backdoor by leveraging anonymized network routing and multi-stage obfuscation. Organizations must prioritize behavioral monitoring of script interpreters and restrict the use of removable media to prevent significant financial loss from wallet-address hijacking.
Microsoft.com Published by Microsoft Defender Security Research Team and Microsoft Defender Experts
Read original