TL;DR

Microsoft has identified a new malware named Crypto Clipper that spreads through USB drives, monitors clipboard data for cryptocurrency info, and exfiltrates data via a covert Tor connection. The malware also functions as a lightweight backdoor, complicating detection efforts. Security researcher says Microsoft built a Bitlocker backdoor, releases exploit.

Microsoft has identified a new self-propagating malware, dubbed Crypto Clipper, that spreads through USB drives, monitors for cryptocurrency wallet data, and exfiltrates information via a covert Tor connection. Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor. This discovery highlights an evolving threat landscape targeting cryptocurrency users and security infrastructure.

According to Microsoft, Crypto Clipper is a lightweight malware that propagates via infected USB drives, specifically through .lnk shortcut files that execute malicious code when plugged into a device. Once active, it checks whether it has already been installed on the system; if not, it downloads additional components through a Tor proxy, ensuring anonymity. The malware monitors the clipboard for patterns resembling wallet addresses or seed phrases, and when detected, takes five screenshots over a ten-second window. Both the stolen credentials and the screenshots are transmitted to attacker-controlled servers via a Tor network, utilizing a SOCKS5 proxy for routing.

Microsoft states that Crypto Clipper does not depend on traditional command-and-control (C2) infrastructure or traditional installers. Instead, it deploys a portable Tor client, blends data theft with remote code execution, and uses file naming obfuscation techniques to conceal its presence on infected drives. The malware’s design aims for stealth and persistence, making it difficult for standard security measures to detect or block.

Implications for Cryptocurrency Security

This malware’s ability to steal cryptocurrency credentials and seed phrases directly threatens users’ digital assets, especially given its stealthy, lightweight design that complicates detection. A security researcher says Microsoft secretly built a backdoor into BitLocker, releases an exploit. Its use of Tor and proxy techniques enhances attacker anonymity, potentially enabling sustained campaigns against targeted individuals or organizations. The discovery underscores the need for heightened security practices around USB device usage and clipboard monitoring.

BUISAMG Data Blocker, USB A & USB C Data Blocker for iphone17 16 and Any USB C Mobile Phone Charge, Protect Against Juice Jacking, Refuse Hacking, Only Charging (Red 6-Pack)

BUISAMG Data Blocker, USB A & USB C Data Blocker for iphone17 16 and Any USB C Mobile Phone Charge, Protect Against Juice Jacking, Refuse Hacking, Only Charging (Red 6-Pack)

【Combination set】: More affordable, The data blocker combination kit shown in the main image, which can meet your…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Evolution of Malware Targeting Cryptocurrency

Recent years have seen an increase in malware targeting cryptocurrency assets, including clipboard hijacking and credential theft. Crypto Clipper’s emergence adds a new dimension by combining file-based propagation with covert exfiltration channels. Microsoft’s detection follows reports of similar threats exploiting removable media and remote code execution techniques, reflecting the growing sophistication of financially motivated malware.

“Crypto Clipper deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

— Microsoft security team

Kingston Ironkey Locker+ 50 G2 64GB Encrypted USB Drive | FIPS 197 | AES-XTS Protection | Multi-Password Security | USB 3.2 Gen 1 | IKLP50G2/64GB

Kingston Ironkey Locker+ 50 G2 64GB Encrypted USB Drive | FIPS 197 | AES-XTS Protection | Multi-Password Security | USB 3.2 Gen 1 | IKLP50G2/64GB

XTS-AES 256-bit hardware-encryption

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Scope and Potential Targets

Microsoft has not disclosed the full scope of Crypto Clipper’s deployment or specific targets. It remains unclear how widespread the malware is, whether it has been used in active campaigns, or if additional variants exist. Details about its command-and-control infrastructure and potential for persistence are still emerging.

Amazon

clipboard monitoring security software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Monitoring and Mitigation Strategies

Security researchers and organizations are expected to analyze the malware further, develop detection signatures, and share mitigation strategies. Users are advised to disable autorun features for USB drives, monitor clipboard activity, and employ endpoint security solutions capable of detecting suspicious file activity and network behavior. Further updates on the malware’s evolution and potential countermeasures are anticipated in the coming weeks.

Plugable USB Data Blocker, Protect Against Juice Jacking at Public USB Ports, Defend Unwanted Data Transfers and Hijacking, Charging Safely, Fast 1A Charge-Only Adapter for Android, Apple iOS Devices

Plugable USB Data Blocker, Protect Against Juice Jacking at Public USB Ports, Defend Unwanted Data Transfers and Hijacking, Charging Safely, Fast 1A Charge-Only Adapter for Android, Apple iOS Devices

Safe Charging: The Plugable USB-MC1 adapter transforms any USB data port into a USB data blocker and charge-only…

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does Crypto Clipper spread?

Crypto Clipper spreads primarily through infected USB drives via malicious .lnk shortcut files that execute when plugged into a device.

What kind of data does it steal?

It monitors the clipboard for cryptocurrency wallet addresses or seed phrases and captures screenshots of the device screen when such data is detected.

How does it transmit stolen data?

The malware uses a Tor network connection via a SOCKS5 proxy to send data anonymously to attacker-controlled servers.

Is this malware currently active?

Microsoft has detected its presence and described its capabilities, but it is not yet clear how widespread or actively deployed Crypto Clipper is.

What can users do to protect themselves?

Users should disable autorun for USB devices, monitor clipboard activity, use security software capable of detecting unusual file or network activity, and avoid plugging unknown drives into their systems.

Source: Ars Technica


You May Also Like

LLMs are eroding my software engineering career and I don’t know what to do

Many experienced software engineers report their skills are being replaced by AI tools, raising concerns about job security and future prospects.

Japan suspected of near $30bn interventions in thin Golden Week trading

Japanese authorities are suspected of intervening in the currency markets with over $28 billion during Golden Week, amid yen-selling concerns.

Idempotency is easy until the second request is different

Understanding why idempotency is straightforward until the second request differs, highlighting key issues for API reliability and design.

Indonesia’s move to change banking rules unsettles private lenders

Indonesia’s financial authority plans to amend banking regulations to support government programs, unsettling private lenders and raising concerns over lending practices.