Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Microsoft discovers new lightweight backdoor that steals cryptocurrency

Microsoft discovers new lightweight backdoor that steals cryptocurrency

Posted on June 19, 2026 By safdargal12 No Comments on Microsoft discovers new lightweight backdoor that steals cryptocurrency
Blog

Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.

A lightweight backdoor

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

Microsoft said it observed Crypto Clipper spreading through .lnk file on a USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks whether it is already installed on the machine. If it isn’t, the malware downloads it through the Tor proxy. To better conceal evidence of the worm, the malware scans the infected USB drive and names the .lnk files with similar names.



Source link

Post Views: 1

Post navigation

❮ Previous Post: Honor X80 Pro Max will sport a 10,000-nit display
Next Post: Grave Seasons Lets You Date the Serial Killer Plaguing Your Cute Town ❯

You may also like

GM joins race to build batteries for AI data centers and the grid
Blog
GM joins race to build batteries for AI data centers and the grid
June 9, 2026
Get ready with the latest beta releases – Latest News
Blog
Get ready with the latest beta releases – Latest News
April 25, 2026
I found a hidden way to wear the Fitbit Air that Google didn’t tell you about
Blog
I found a hidden way to wear the Fitbit Air that Google didn’t tell you about
May 30, 2026
One UI 9 slipped in one quiet change that Samsung phone thieves will hate
Blog
One UI 9 slipped in one quiet change that Samsung phone thieves will hate
May 30, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Source: Elastic agrees to buy CRV-backed DeductiveAI for up to $85M
  • Grave Seasons Lets You Date the Serial Killer Plaguing Your Cute Town
  • Microsoft discovers new lightweight backdoor that steals cryptocurrency
  • Honor X80 Pro Max will sport a 10,000-nit display
  • Host custom HTML applications inside Datasette

Recent Comments

  1. blood strike top up on NYC Mayor Zohran Mamdani takes to Twitch to chat with New Yorkers
  2. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown