Microsoft identifies malware ‘worm’ that hijacks crypto wallets, spreads through USB drives

Share This Post

The wallet-stealing component monitors Windows’ clipboard, the hidden temporary memory used for copy-and-paste operations, roughly every 500 milliseconds. When a user copies a crypto wallet seed phrase or a private key for a Bitcoin or Ethereum wallet, the malware captures that data and sends it to the attacker’s server over the Tor network, an open-source overlay that provides anonymous communication. It also takes five screenshots, ten seconds apart, and sends those along too.

The risk doesn’t end there.

If a user copies a recipient address to send funds, the worm silently replaces it with an attacker-controlled address before the user pastes, so the transfer goes to the attacker without any visible cue.

Lastly, the worm propagates when a clean USB drive is plugged into the computer. It scans the clean USB drive for ordinary files, Word docs, Excel sheets and PDFs, replaces them with new shortcut files using the same names and infects the drive. Then the cycle continues.

Microsoft recommends disabling AutoRun for removable media, blocking .lnk file execution on USB drives via group policy and restricting script hosts such as wscript.exe and cscript.exe. Microsoft Defender customers can also run hunting queries to check for related activity, including connections to a local Tor proxy on port 9050.

Related Posts

Mounting AI costs and weaker performance are driving investors toward AI infrastructure

The biggest winners from the rotation have been memory...

Smart-contract and DeFi coins lead losses as BTC price wilts for 4th straight day

The largest cryptocurrencies remained under pressure for a fourth...

GoMining challenges Jack Dorsey’s Square with a pure BTC payment rail

Bitcoin BTC$62,709.12 mining company GoMining said it is making...

Franklin Templeton proposes new funds that turn dividends into BTC: Crypto Daily

If approved, the ETFs could begin trading as early...

Bitcoin Q3 Bottom Could Spark ‘Complete Disbelief’ Above $50,000

Bitcoin (BTC) could reach its new “macro bottom” by...

Federal Reserve Moves To Close Stablecoin Loopholes With New Customer ID Rules

The Federal Reserve proposed Thursday that payment...