
Microsoft says it has discovered new self-promoting malware that spreads via USB drives to search for cryptocurrency credentials, then sends them to servers controlled by attackers.
The company named the worm Crypto Clipper because it monitors the contents of device buffers for patterns matching wallet addresses or key phrases. When malware is detected, it also takes five screenshots within 10 seconds. Both the credentials and screenshots are then sent to the attacker via Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs cannot capture both the sender and receiver IP addresses. Crypto Clipper establishes a Tor connection using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server and then forwards it to its final destination.
Light rear door
“The performance of this scissor is remarkable because it does not depend on a traditional installer or open IP-based C2 infrastructure,” Microsoft said. he said on Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and combines data theft with remote code execution, turning financially motivated theft into a lightweight backdoor.”
Microsoft said it was monitoring the spread of Crypto Clipper .link file on the USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks to see if it’s already installed on the machine. If not, the malware downloads it through the Tor proxy. To better hide evidence of the worm, the malware scans the infected USB drive and renames the .lnk files with similar names.





