New Crypto Clipper Uses Windows Script Host and ActiveXObject for Remote Code Execution
ID: a49addd8-2444-584d-a8f9-4e6808d8dd27
STIX ID: report--a49addd8-2444-584d-a8f9-4e6808d8dd27
Feed Name: GBHackers
**Executive summary:** A Windows-based cryptocurrency clipper and worm active since February 2026 propagates via malicious .lnk shortcuts on removable media, drops obfuscated JScript payloads that use WScript/ActiveX to steal clipboard BIP39 seeds and private keys, replaces copied wallet addresses with attacker-controlled values, and routes all command-and-control and exfiltration over a bundled Tor client via a local SOCKS5 proxy (localhost:9050); the malware also supports runtime EVAL commands for remote code execution, creates persistence through scheduled tasks and Defender exclusions, and is covered by multiple IOCs (SHA-256 hashes, a portable Tor filename, and numerous .onion C2 domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
