logo

Hackers Use Tor-Routed C2 and Local SOCKS5 Proxy to Control Crypto Clipper Malware

ID: 875bb901-f820-5fd3-bf2c-e8abee7c7092

STIX ID: report--875bb901-f820-5fd3-bf2c-e8abee7c7092

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Varshini

...
...

A sophisticated Windows cryptocurrency clipper and worm campaign active since February 2026 spreads via malicious .lnk files on USB drives, deploying a worm to propagate and a stealer that monitors the clipboard for BIP39 seed phrases, private keys, and crypto addresses, replaces copied addresses with attacker-controlled ones, captures screenshots, and exfiltrates data over Tor (bundled ugate.exe to localhost:9050) to .onion C2 endpoints; the malware uses scheduled tasks for persistence, PyArmor/PyInstaller obfuscation, simple anti-analysis checks, and includes multiple SHA-256 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.