Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Microsoft discovers new lightweight backdoor that steals cryptocurrency

Microsoft discovers new lightweight backdoor that steals cryptocurrency

Posted on June 19, 2026 By safdargal12 No Comments on Microsoft discovers new lightweight backdoor that steals cryptocurrency
Blog

Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.

A lightweight backdoor

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

Microsoft said it observed Crypto Clipper spreading through .lnk file on a USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks whether it is already installed on the machine. If it isn’t, the malware downloads it through the Tor proxy. To better conceal evidence of the worm, the malware scans the infected USB drive and names the .lnk files with similar names.



Source link

Post Views: 2

Post navigation

❮ Previous Post: Honor X80 Pro Max will sport a 10,000-nit display
Next Post: Grave Seasons Lets You Date the Serial Killer Plaguing Your Cute Town ❯

You may also like

The climate tech IPO window could finally be cracking open
Blog
The climate tech IPO window could finally be cracking open
April 26, 2026
YouTube TV’s Customizable Multiview Could Let You Watch 4 Shows on One Screen
Blog
YouTube TV’s Customizable Multiview Could Let You Watch 4 Shows on One Screen
April 24, 2026
This Spotify update lets you share the best part of a podcast
Blog
This Spotify update lets you share the best part of a podcast
May 28, 2026
US hantavirus case was false positive; outbreak cases drop from 11 to 10
Blog
US hantavirus case was false positive; outbreak cases drop from 11 to 10
May 16, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Apple reportedly considering price hikes as memory prices surge
  • Barret Zoph is out at OpenAI again after just five months
  • The new Honor Watch 6 packs a massive 980mAh battery in a slender 10.8mm body
  • Source: Elastic agrees to buy CRV-backed DeductiveAI for up to $85M
  • Grave Seasons Lets You Date the Serial Killer Plaguing Your Cute Town

Recent Comments

  1. blood strike top up on NYC Mayor Zohran Mamdani takes to Twitch to chat with New Yorkers
  2. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown