Microsoft has discovered a USB worm designed to steal cryptocurrency: the malicious Crypto Clipper program spreads via removable drives, monitors the clipboard on personal computers, and can transmit stolen data through the Tor network.
How a Computer Gets Infected via USB Flash Drive
According to Microsoft experts, the attack starts with malicious LNK shortcut files that attackers place on removable drives. When such a USB flash drive is connected to a computer, the program checks if its components are present in the system and then downloads additional modules if necessary.
To communicate with the attack operators, Crypto Clipper uses a hidden channel based on a local Tor network client and a proxy server. This approach helps the malware mask its network activity and makes it harder to quickly determine where the data is going.
Why Crypto Clipper Is Harder to Track
Unlike many modern threats, this software does not rely on a traditional command-and-control server. Instead of the classic scheme where a server as software receives commands and relays them to infected devices, the malware operates through the anonymized Tor network.
Using the Tor network complicates investigations: it is harder for specialists to determine the source of the attack, trace connection routes, and distinguish dangerous traffic from normal Windows activity.
What Exactly the Malware Steals
The main target of Crypto Clipper is cryptocurrency and data related to users’ wallets. Once inside the system, the program starts monitoring the clipboard, searching for wallet addresses, seed phrases for account recovery, and other information that could help attackers gain control over digital assets.
The consequences for the owner can be serious: loss of funds, leakage of personal data, and loss of control over the wallet. If attackers obtain the seed phrase, it may be impossible to restore access to assets.
If a user copies an address for a transfer, the Clipper can substitute it with the attackers’ details. As a result, funds—including bitcoin and other digital currencies—may go not to the intended recipient but to the attackers’ wallet, and the owner may notice the substitution too late.
In addition to intercepting text, the malware takes a series of screenshots. This way, attackers get context about the user’s actions: what operations are being performed, which windows are open, and exactly how the user interacts with crypto services.
Masquerading as Ordinary Files and the Risk for Windows Users
Microsoft notes that Crypto Clipper tries to appear harmless. Its files are named similarly to ordinary objects on a USB drive. Because of this, the threat is harder to notice not only for regular users but also for system administrators.
What Security Measures Microsoft Recommends
To reduce the risk of infection from USB drives, you should follow a few rules:
- Use antivirus software and keep system protection enabled.
- Scan removable drives before opening files.
- Be cautious with shortcuts on flash drives, especially if they look like regular documents or folders.
- Do not manually run suspicious files.
- Use Microsoft Defender Antivirus and Windows Defender to detect such threats.
The danger of this threat is that it combines several functions at once:
- Spyware.
- Remote command execution.
- Data interception.
- Covert data transmission.
In essence, this is not just a single virus but a comprehensive tool for stealing cryptocurrency assets.
What Names and Terms You May Encounter When Checking the System
Main names and terms when checking the system:
- Microsoft — the company whose experts discovered the threat.
- Tor — the anonymized network through which the malware transmits stolen data.
- Crypto Clipper — the malware that monitors the clipboard and can substitute wallet addresses.
- Clipper — a short name for the same malware.
- Windows — the system where experts look for signs of infection.
- Microsoft Defender Antivirus and Windows Defender — security tools that help detect such threats.
- Windows API and curl — technical terms that may be encountered when analyzing such attacks.
- Proxy server and data transfer protocol — elements of the hidden communication channel with attack operators.
- Spyware — a term for spying software.
There may also be unrelated name matches: Defender in football, Defender as a game, Microsoft Excel, and SpaceX. These are not related to the attack itself.
Earlier, Microsoft also acknowledged a widespread bug in the June Windows update.
{
“@context”: “https://schema.org”,
“@type”: “Article”,
“about”: [
{
“@type”: “Organization”,
“name”: “Microsoft”
},
{
“@type”: “SoftwareApplication”,
“name”: “Crypto Clipper”
},
{
“@type”: “Organization”,
“name”: “Tor”
},
{
“@type”: “Product”,
“name”: “Windows”
},
{
“@type”: “SoftwareApplication”,
“name”: “Microsoft Defender Antivirus”
},
{
“@type”: “Thing”,
“name”: “Cryptocurrency”
},
{
“@type”: “Thing”,
“name”: “Clipboard”
},
{
“@type”: “Thing”,
“name”: “Spyware”
},
{
“@type”: “Thing”,
“name”: “Proxy Server”
}
]
}
