AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Microsoft has identified a new malware named Crypto Clipper that spreads through USB drives, monitors clipboard data for cryptocurrency info, and exfiltrates data via a covert Tor connection. The malware also functions as a lightweight backdoor, complicating detection efforts. Security researcher says Microsoft built a Bitlocker backdoor, releases exploit.

Microsoft has identified a new self-propagating malware, dubbed Crypto Clipper, that spreads through USB drives, monitors for cryptocurrency wallet data, and exfiltrates information via a covert Tor connection. Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor. This discovery highlights an evolving threat landscape targeting cryptocurrency users and security infrastructure.

According to Microsoft, Crypto Clipper is a lightweight malware that propagates via infected USB drives, specifically through .lnk shortcut files that execute malicious code when plugged into a device. Once active, it checks whether it has already been installed on the system; if not, it downloads additional components through a Tor proxy, ensuring anonymity. The malware monitors the clipboard for patterns resembling wallet addresses or seed phrases, and when detected, takes five screenshots over a ten-second window. Both the stolen credentials and the screenshots are transmitted to attacker-controlled servers via a Tor network, utilizing a SOCKS5 proxy for routing.

Microsoft states that Crypto Clipper does not depend on traditional command-and-control (C2) infrastructure or traditional installers. Instead, it deploys a portable Tor client, blends data theft with remote code execution, and uses file naming obfuscation techniques to conceal its presence on infected drives. The malware’s design aims for stealth and persistence, making it difficult for standard security measures to detect or block.

Implications for Cryptocurrency Security

This malware’s ability to steal cryptocurrency credentials and seed phrases directly threatens users’ digital assets, especially given its stealthy, lightweight design that complicates detection. A security researcher says Microsoft secretly built a backdoor into BitLocker, releases an exploit. Its use of Tor and proxy techniques enhances attacker anonymity, potentially enabling sustained campaigns against targeted individuals or organizations. The discovery underscores the need for heightened security practices around USB device usage and clipboard monitoring.

Amazon

USB data blocker for cryptocurrency security

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Evolution of Malware Targeting Cryptocurrency

Recent years have seen an increase in malware targeting cryptocurrency assets, including clipboard hijacking and credential theft. Crypto Clipper’s emergence adds a new dimension by combining file-based propagation with covert exfiltration channels. Microsoft’s detection follows reports of similar threats exploiting removable media and remote code execution techniques, reflecting the growing sophistication of financially motivated malware.

“Crypto Clipper deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

— Microsoft security team

Amazon

hardware encrypted USB drives

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Scope and Potential Targets

Microsoft has not disclosed the full scope of Crypto Clipper’s deployment or specific targets. It remains unclear how widespread the malware is, whether it has been used in active campaigns, or if additional variants exist. Details about its command-and-control infrastructure and potential for persistence are still emerging.

Amazon

clipboard monitoring security software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Monitoring and Mitigation Strategies

Security researchers and organizations are expected to analyze the malware further, develop detection signatures, and share mitigation strategies. Users are advised to disable autorun features for USB drives, monitor clipboard activity, and employ endpoint security solutions capable of detecting suspicious file activity and network behavior. Further updates on the malware’s evolution and potential countermeasures are anticipated in the coming weeks.

Amazon

USB secure data transfer device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does Crypto Clipper spread?

Crypto Clipper spreads primarily through infected USB drives via malicious .lnk shortcut files that execute when plugged into a device.

What kind of data does it steal?

It monitors the clipboard for cryptocurrency wallet addresses or seed phrases and captures screenshots of the device screen when such data is detected.

How does it transmit stolen data?

The malware uses a Tor network connection via a SOCKS5 proxy to send data anonymously to attacker-controlled servers.

Is this malware currently active?

Microsoft has detected its presence and described its capabilities, but it is not yet clear how widespread or actively deployed Crypto Clipper is.

What can users do to protect themselves?

Users should disable autorun for USB devices, monitor clipboard activity, use security software capable of detecting unusual file or network activity, and avoid plugging unknown drives into their systems.

Source: Ars Technica


FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

The bank account in the chat. How personal finance became an agentic on-ramp.

OpenAI launched a preview of personal finance features in ChatGPT, enabling bank account connections for Pro users, signaling a shift toward agentic finance interfaces.

$WEST $VELO $ATAI Tech and biotech stocks complete multi-week consolidation for a breakout. Only @letoilelopes times range breakouts perfectly for maximum gains.

Major tech and biotech stocks $WEST, $VELO, and $ATAI have finished a multi-week consolidation and are now poised for potential breakout moves, according to market signals.

Sam Altman says Elon Musk’s mind games were damaging OpenAI

OpenAI CEO Sam Altman testified that Elon Musk’s management style caused significant damage to the company’s culture during Musk’s lawsuit.

Week Three — Foundation model vs Brownian motion. Kronos on five-minute BTC.

Kronos, a foundation model, was tested against a Brownian motion baseline for 5-minute BTC predictions; results show no significant improvement.