logo

Tor-Based Clipper Malware Targets Wallet Seed Phrases

ID: b03c1828-db23-5d75-81ad-42483427f98e

STIX ID: report--b03c1828-db23-5d75-81ad-42483427f98e

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: Pierluigi Paganini

...
...

Microsoft-tracked Tor-based clipper campaign uses malicious .lnk USB shortcuts to deploy a Python-based clipboard stealer that captures BIP39 seed phrases, private keys, and wallet addresses, replaces copied addresses with attacker-controlled ones, takes frequent screenshots, and exfiltrates data via a bundled Tor client to .onion C2s; the malware supports remote JavaScript execution, employs runtime decryption and obfuscation, is detected as Trojan:Win32/CryptoBandits.A, and defenders are advised to monitor wscript/cscript activity, localhost:9050 proxy use, and block .lnk execution from removable drives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.