Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Yen slides past 161 against the dollar, nearing 40-year low and reviving intervention bets

    June 19, 2026

    Sleep and light: the science behind Qantas’ bet on 20-hour flights

    June 19, 2026

    As China looms, Taiwan makes more drones for defense and the US military

    June 19, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»Microsoft discovers new lightweight backdoor that steals cryptocurrency
    Tech

    Microsoft discovers new lightweight backdoor that steals cryptocurrency

    franperez66q@protonmail.comBy franperez66q@protonmail.comJune 19, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

    The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.

    A lightweight backdoor

    “The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

    Microsoft said it observed Crypto Clipper spreading through .lnk file on a USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks whether it is already installed on the machine. If it isn’t, the malware downloads it through the Tor proxy. To better conceal evidence of the worm, the malware scans the infected USB drive and names the .lnk files with similar names.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    As China looms, Taiwan makes more drones for defense and the US military

    June 19, 2026

    A bold satellite rescue mission came together in record time, but will it work?

    June 19, 2026

    Jim Cramer says next week’s economic data will drive the markets

    June 19, 2026

    FDA advisors unanimously vote to approve Moderna’s mRNA after agency drama

    June 18, 2026

    Amazon investigating engineers who criticized AI data center expansion

    June 18, 2026

    NASA asks Northrop Grumman to stop working on lunar HALO module

    June 18, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Yen slides past 161 against the dollar, nearing 40-year low and reviving intervention bets

    June 19, 2026

    Sleep and light: the science behind Qantas’ bet on 20-hour flights

    June 19, 2026

    As China looms, Taiwan makes more drones for defense and the US military

    June 19, 2026

    Why Japan’s intervention and a rate hike didn’t prop up the yen more

    June 19, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.