Microsoft Warns of New USB-Based Malware Targeting Crypto Users
Microsoft’s Defender team has alerted users to a new malware threat that spreads via USB flash drives, exploiting Windows shortcut (.lnk) files to infect devices. The malware, dubbed a ‘clipper,’ continuously monitors the clipboard for cryptocurrency addresses and substitutes them with addresses controlled by attackers, enabling theft of funds during transactions.
Once a USB drive is inserted into an infected computer, the malware copies itself to the drive and replaces legitimate files with malicious shortcuts. When executed, these shortcuts trigger the infection, which also employs Tor-powered communication to avoid detection and takes measures to evade antivirus scanning.
In addition to address swapping, the malware scans the infected device’s memory every 500 milliseconds for addresses of popular cryptocurrencies—including Bitcoin, Tron, and Monero—as well as BIP39 seed phrases (12 or 24 words). Upon detecting seed phrases, it sends them to attackers alongside up to five screenshots to provide context about wallet contents and funds.
‘The malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,’ Microsoft’s Defender team stated. To mitigate risks, Microsoft recommends disabling autorun for removable media and blocking execution of shortcuts from removable drives, as these are the primary propagation vectors.
This alert underscores growing threats targeting cryptocurrency users through physical media, highlighting the need for robust security practices when handling USB devices.
Source: https://news.bitcoin.com/microsoft-warns-of-new-usb-based-malware-targeting-crypto-users/