logo

New Crypto Clipper Uses Windows Script Host and ActiveXObject for Remote Code Execution

ID: a49addd8-2444-584d-a8f9-4e6808d8dd27

STIX ID: report--a49addd8-2444-584d-a8f9-4e6808d8dd27

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Mayura Kathir

...
...

**Executive summary:** A Windows-based cryptocurrency clipper and worm active since February 2026 propagates via malicious .lnk shortcuts on removable media, drops obfuscated JScript payloads that use WScript/ActiveX to steal clipboard BIP39 seeds and private keys, replaces copied wallet addresses with attacker-controlled values, and routes all command-and-control and exfiltration over a bundled Tor client via a local SOCKS5 proxy (localhost:9050); the malware also supports runtime EVAL commands for remote code execution, creates persistence through scheduled tasks and Defender exclusions, and is covered by multiple IOCs (SHA-256 hashes, a portable Tor filename, and numerous .onion C2 domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.