Close Menu
    What's Hot

    Trump’s Iran Deal Leaves Hormuz Less Than Open

    Trump Redirects Millions From Secret Service Amid White House Construction

    J.D. Vance Sells the Trump Administration’s U.S.-Iran Peace Deal

    Facebook X (Twitter) Instagram
    Trending
    • Trump’s Iran Deal Leaves Hormuz Less Than Open
    • Trump Redirects Millions From Secret Service Amid White House Construction
    • J.D. Vance Sells the Trump Administration’s U.S.-Iran Peace Deal
    • Man Forced Boy, 3, Into Crocodile Pen at English Zoo, Police Say
    • Snap spins off AI video team into new company, Dotmo, due to costs
    • The Washington Outlet NOTUS Won’t Be ‘The Star’ After All
    • Gold Royalty Corp. (GROY) Analyst/Investor Day Transcript
    • Argentina star Lionel Messi’s father, Jorge, has health issue, family confirm
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

    adminBy adminJune 18, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 18, 2026Malware / Cryptocurrency

    Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

    Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026.

    “The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command-and-control] server,” the Microsoft Defender Security Research Team said in an analysis published Tuesday. “It carries out high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution.”

    “The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure. Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

    Cybersecurity

    Clipper malware refers to a type of malicious software that silently monitors a user’s clipboard and intercepts sensitive data pasted into the short-term buffer. It primarily targets cryptocurrency transactions by substituting wallet address strings that match known blockchain address patterns to reroute them to addresses under their control.

    The attacks involve distributing a malicious Windows Shortcut (LNK) file via USB storage devices, opening which triggers a worm component that checks is the machine is already infected and only proceeds to fetch the payload from a remote server if it’s not present. A second module deployed is the clipper that harvests and exfiltrates cryptocurrency wallet information.

    The LNK payload scans the USB device for common document types like DOC, XLSX, and PDF, and if found, hides them and creates new LNK files with the same file names and containing arguments that line to the worm component. Thus, when an unsuspecting user launches the shortcut thinking they are opening a harmless document, it triggers the execution of the malware.

    The worm component, besides ensuring propagation to other uncompromised USB drives, deploys scheduled tasks as a form of persistence for both the worm component and the stealer component. The clipper, for its part, uses WScript and ActiveXObject to interact with the operating system, and exits if Task Manager is among the list of actively running processes to evade detection.

    In the final stage, the malware launches a renamed Tor binary in a hidden window, generates a unique victim identifier, and registers it with the external server. Once this step is complete, the malware enters a continuous loop, periodically polling the C2 server for instructions while simultaneously monitoring the clipboard about every 500 milliseconds to extract seed phrases and private keys.

    Cybersecurity

    “It also hijacks cryptocurrency addresses by replacing copied wallet values with attacker-controlled alternatives and uploads screenshots through Tor,” Microsoft said. “If the C2 returns an EVAL response, the malware executes attacker-supplied code at runtime.”

    The tech giant has recommended that defenders prioritize behavioral detections over static signatures, specifically looking for PowerShell-based screen capture and the use of WScript, CScript, or related script engines for launching curl, cmd.exe, PowerShell, or unexpected executables.

    Other mitigations include disabling AutoRun/AutoPlay for all removable media, blocking LNK execution from removable drives via Group Policy Objects (GPOs), restricting unnecessary use of wscript.exe or cscript.exe, and review clipboard-related and screen-capture behaviors on devices handling sensitive financial workflows.

    campaign Clipper Details LNK Malware Microsoft TorBased USB Windows Worm
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy were Waymo cars driving into active construction zones?
    Next Article How the Peter Thiel-Linked Dialog Club Secretly Ranks Its Members
    admin
    • Website

    Related Posts

    F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

    June 18, 2026

    ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security

    June 18, 2026

    Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

    June 18, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump’s Iran Deal Leaves Hormuz Less Than Open

    Trump Redirects Millions From Secret Service Amid White House Construction

    J.D. Vance Sells the Trump Administration’s U.S.-Iran Peace Deal

    Man Forced Boy, 3, Into Crocodile Pen at English Zoo, Police Say

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by