TL;DR

Microsoft has identified a new malware named Crypto Clipper that spreads through USB drives, monitors clipboard data for cryptocurrency info, and exfiltrates data via a covert Tor connection. The malware also functions as a lightweight backdoor, complicating detection efforts. Security researcher says Microsoft built a Bitlocker backdoor, releases exploit.

Microsoft has identified a new self-propagating malware, dubbed Crypto Clipper, that spreads through USB drives, monitors for cryptocurrency wallet data, and exfiltrates information via a covert Tor connection. Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor. This discovery highlights an evolving threat landscape targeting cryptocurrency users and security infrastructure.

According to Microsoft, Crypto Clipper is a lightweight malware that propagates via infected USB drives, specifically through .lnk shortcut files that execute malicious code when plugged into a device. Once active, it checks whether it has already been installed on the system; if not, it downloads additional components through a Tor proxy, ensuring anonymity. The malware monitors the clipboard for patterns resembling wallet addresses or seed phrases, and when detected, takes five screenshots over a ten-second window. Both the stolen credentials and the screenshots are transmitted to attacker-controlled servers via a Tor network, utilizing a SOCKS5 proxy for routing.

Microsoft states that Crypto Clipper does not depend on traditional command-and-control (C2) infrastructure or traditional installers. Instead, it deploys a portable Tor client, blends data theft with remote code execution, and uses file naming obfuscation techniques to conceal its presence on infected drives. The malware’s design aims for stealth and persistence, making it difficult for standard security measures to detect or block.

Implications for Cryptocurrency Security

This malware’s ability to steal cryptocurrency credentials and seed phrases directly threatens users’ digital assets, especially given its stealthy, lightweight design that complicates detection. A security researcher says Microsoft secretly built a backdoor into BitLocker, releases an exploit. Its use of Tor and proxy techniques enhances attacker anonymity, potentially enabling sustained campaigns against targeted individuals or organizations. The discovery underscores the need for heightened security practices around USB device usage and clipboard monitoring.

Data Blocker, USB C Data Blocker Protect Against Juice Jacking, 6-pcs

Data Blocker, USB C Data Blocker Protect Against Juice Jacking, 6-pcs

【Combination set】: More affordable, The data blocker combination kit shown in the main image, which can meet your…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Evolution of Malware Targeting Cryptocurrency

Recent years have seen an increase in malware targeting cryptocurrency assets, including clipboard hijacking and credential theft. Crypto Clipper’s emergence adds a new dimension by combining file-based propagation with covert exfiltration channels. Microsoft’s detection follows reports of similar threats exploiting removable media and remote code execution techniques, reflecting the growing sophistication of financially motivated malware.

“Crypto Clipper deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

— Microsoft security team

Integral 32GB Crypto-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Rugged Double-Layer Waterproof Design

Integral 32GB Crypto-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive – Certified to FIPS 197, Brute-Force Password Attack Protection & Rugged Double-Layer Waterproof Design

Certified to FIPS 197 – High-level information security standard approved by the U.S. Government

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Scope and Potential Targets

Microsoft has not disclosed the full scope of Crypto Clipper’s deployment or specific targets. It remains unclear how widespread the malware is, whether it has been used in active campaigns, or if additional variants exist. Details about its command-and-control infrastructure and potential for persistence are still emerging.

Amazon

clipboard monitoring security software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Monitoring and Mitigation Strategies

Security researchers and organizations are expected to analyze the malware further, develop detection signatures, and share mitigation strategies. Users are advised to disable autorun features for USB drives, monitor clipboard activity, and employ endpoint security solutions capable of detecting suspicious file activity and network behavior. Further updates on the malware’s evolution and potential countermeasures are anticipated in the coming weeks.

JSAUX USB Data Blocker & USB C Data Blocker, Charge-Only, 4-Pack, Grey

JSAUX USB Data Blocker & USB C Data Blocker, Charge-Only, 4-Pack, Grey

The Ultimate Data Guardian: Worried about the risk of mobile phone data leakage or viruses when using public…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does Crypto Clipper spread?

Crypto Clipper spreads primarily through infected USB drives via malicious .lnk shortcut files that execute when plugged into a device.

What kind of data does it steal?

It monitors the clipboard for cryptocurrency wallet addresses or seed phrases and captures screenshots of the device screen when such data is detected.

How does it transmit stolen data?

The malware uses a Tor network connection via a SOCKS5 proxy to send data anonymously to attacker-controlled servers.

Is this malware currently active?

Microsoft has detected its presence and described its capabilities, but it is not yet clear how widespread or actively deployed Crypto Clipper is.

What can users do to protect themselves?

Users should disable autorun for USB devices, monitor clipboard activity, use security software capable of detecting unusual file or network activity, and avoid plugging unknown drives into their systems.

Source: Ars Technica


You May Also Like

AI Trading Bot — Week Two: The candidate edge collapsed

The initial advantage of a new AI trading bot has vanished after two weeks, raising questions about its long-term viability and market impact.

England central banker says global stablecoin rules will ‘wrestle’ with US

Bank of England Governor Andrew Bailey warns international regulators will face challenges in establishing stablecoin rules, primarily due to US policies.

DESRI and Meta sign 850 MW of new power purchase agreements, pushing partnership past 2.5 GW

Meta and D.E. Shaw Renewable Investments have secured 850 MW of new renewable energy contracts for 2026, boosting their partnership and renewable capacity.

The Steve Jobs $1 coin goes on sale today starting at $61 for a roll

The US Mint begins selling the Steve Jobs $1 innovation coin today, priced at $61 for a roll of 25 coins, honoring the tech pioneer’s legacy.