Hackers Use Tor-Routed C2 and Local SOCKS5 Proxy to Control Crypto Clipper Malware
ID: 875bb901-f820-5fd3-bf2c-e8abee7c7092
STIX ID: report--875bb901-f820-5fd3-bf2c-e8abee7c7092
Feed Name: Cyber Press
A sophisticated Windows cryptocurrency clipper and worm campaign active since February 2026 spreads via malicious .lnk files on USB drives, deploying a worm to propagate and a stealer that monitors the clipboard for BIP39 seed phrases, private keys, and crypto addresses, replaces copied addresses with attacker-controlled ones, captures screenshots, and exfiltrates data over Tor (bundled ugate.exe to localhost:9050) to .onion C2 endpoints; the malware uses scheduled tasks for persistence, PyArmor/PyInstaller obfuscation, simple anti-analysis checks, and includes multiple SHA-256 IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
