Microsoft discovers new lightweight backdoor that steals cryptocurrency

This self-propagating malware spreads through USB drives, steals wallet credentials, and uses Tor to evade detection.

By Central
Crypto Clipper worm uses Tor and USB propagation to steal cryptocurrency data from infected systems.
Highlights
  • Crypto Clipper spreads via malicious .lnk files on USB drives without traditional installer or C2 infrastructure.
  • The malware monitors clipboard for wallet addresses or seed phrases and captures screenshots for data theft.
  • Users should use hardware wallets, enforce USB hygiene, and monitor for unexpected Tor traffic to stay protected.

Microsoft has identified a new self-propagating worm, tracked as Crypto Clipper, that spreads through USB drives to steal cryptocurrency credentials and exfiltrate them via the Tor network. The malware, detailed in a security advisory published Thursday, represents a significant evolution in financially motivated cyberattacks by combining portable Tor client usage with worm-like propagation and remote code execution capabilities.

Dubbed Crypto Clipper by Microsoft, the malware monitors the contents of a device’s clipboard for patterns consistent with cryptocurrency wallet addresses or seed phrases. Upon detection, the malware captures five screenshots over a 10-second period. Both the stolen credentials and the screenshots are then transmitted to an attacker-controlled server through Tor, leveraging a SOCKS5 proxy to establish the anonymous connection. This technique ensures that network logs cannot capture both the sending and receiving IP addresses, providing robust operational security for the threat actor.

A Lightweight Backdoor with No Traditional Infrastructure

The execution profile of Crypto Clipper is notable for its departure from conventional malware deployment methods. It does not rely on a traditional installer or an exposed IP-based command-and-control (C2) infrastructure. Instead, the worm deploys a portable Tor client, routes all traffic through a local SOCKS5 proxy, and blends data theft with remote code execution. This design effectively transforms what might otherwise be a straightforward credential stealer into a lightweight backdoor capable of further compromise.

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft stated. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

How the Worm Propagates via USB Drives

Microsoft observed Crypto Clipper spreading through malicious .lnk shortcut files stored on USB drives. When an infected USB drive is connected to a Windows device, the executable code within the shortcut file checks whether the malware is already installed on the target machine. If it is not present, the malware downloads the full payload through the established Tor proxy. To evade detection and conceal its presence, the worm scans the infected USB drive and creates new .lnk files using names similar to existing legitimate files on the drive, making the infection more difficult for users to identify manually.

What This Means for Cryptocurrency Users

The discovery underscores the growing sophistication of threats targeting digital asset holders. The use of USB-based propagation is particularly concerning for environments where removable media is frequently used, such as cryptocurrency kiosks, mining rigs, or air-gapped systems used for cold wallet management. The absence of traditional C2 infrastructure means that standard network monitoring tools may fail to detect the outbound communication, as it is routed through Tor and a local proxy.

Furthermore, the malware’s ability to capture screenshots suggests that the attackers are not solely interested in clipboard data. Screenshots can reveal on-screen wallet balances, transaction details, or even two-factor authentication codes displayed in authenticator applications, providing a broader attack surface than clipboard monitoring alone.

How to Protect Against USB-Borne Crypto Malware

Users in the United States, United Kingdom, Australia, and Canada who handle cryptocurrency should take immediate steps to mitigate the risk posed by this and similar threats. The most effective defense involves a combination of physical security, endpoint protection, and operational discipline.

  • Disable AutoPlay for removable media: Ensure that Windows does not automatically execute any code from USB drives. This is the single most effective control against .lnk-based worm propagation.
  • Use a multi-layer endpoint protection solution: Deploy real-time threat detection software that includes behavioral analysis capabilities. Such tools can identify suspicious clipboard monitoring, screenshot capture, and unexpected Tor network connections, even if the malware is not yet on known signature databases.
  • Maintain strict USB device hygiene: Only use USB drives obtained from trusted sources and avoid plugging unknown drives into systems that hold cryptocurrency wallets or private keys.
  • Consider dedicated hardware wallets: For significant cryptocurrency holdings, use a hardware wallet that signs transactions offline, ensuring that private keys never reside on a system that could be compromised by clipboard or screen capture malware.
  • Monitor for unexpected Tor traffic: Network administrators and security-conscious users should investigate any unexplained Tor connections from endpoints that do not require anonymous browsing for legitimate purposes.

What Affected Users Should Do Now

If you suspect that a system has been exposed to an infected USB drive or if you observe unusual clipboard behavior or unauthorized Tor connections, take the following steps immediately. First, disconnect the affected device from any network to prevent further data exfiltration. Second, change all cryptocurrency wallet passwords and seed phrases using a clean, trusted device. Third, enable two-factor authentication on all exchange accounts and custodial wallets. Finally, run a full scan using a reputable anti-malware tool that includes heuristics and behavioral detection. For high-value cryptocurrency holdings, transferring assets to a new wallet generated on a known-clean, air-gapped device is the safest course of action. The threat is active, and prompt action is the most effective remedy.

Share This Article