Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives
ID: fcee2b84-aab0-5090-a4b3-e55f00fa3866
STIX ID: report--fcee2b84-aab0-5090-a4b3-e55f00fa3866
Feed Name: cybersecurityNews.com
A newly discovered crypto-clipper worm propagates via malicious .lnk shortcuts on USB drives, hiding original files and creating look-alike shortcuts that drop obfuscated Python and JavaScript payloads when opened. The malware replaces copied cryptocurrency addresses with attacker-controlled ones, captures screenshots, supports remote EVAL commands, persists via scheduled tasks, and routes all C2 traffic through a bundled Tor client; Microsoft analysts provided numerous SHA-256 hashes and .onion C2 indicators and recommended mitigations such as disabling AutoRun/AutoPlay and blocking .lnk execution from removable media.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
