- Microsoft warns of “Crypto Clipper,” a worm spreading via malicious .LNK files on USB drives
- Malware maintains persistence, connects to Tor C2, enables remote code execution, and steals clipboard crypto data
- It swaps wallet addresses, exfiltrates seed phrases/private keys, and uploads screenshots to assess target value
Microsoft is warning of an ongoing campaign targeting cryptocurrency owners with a clipboard-jacking worm.