Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
ID: e0d17354-de1b-5b3d-94bb-2b544aa9188f
STIX ID: report--e0d17354-de1b-5b3d-94bb-2b544aa9188f
Feed Name: CosmicBytez Labs
Microsoft Threat Intelligence reports an active Windows-targeting clipboard-hijacking (clipper) campaign that replaces copied cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets. The campaign includes a self-spreading USB LNK worm component, Tor-routed C2, multi-currency address targeting, persistence via scheduled tasks and registry run keys, and has resulted in cross-regional financial losses; Microsoft published detection guidance and IOCs (file hashes, scheduled task names, Tor hidden service addresses) for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
