USB worm spreads crypto-stealing malware via Windows shortcut files
ID: bd38ed32-769e-5839-a4e9-0d5b8419bc64
STIX ID: report--bd38ed32-769e-5839-a4e9-0d5b8419bc64
Feed Name: Bleeping Computer
A USB-spreading worm campaign active since at least February distributes a clipboard-stealing 'clipper' that replaces cryptocurrency wallet addresses, captures seed phrases, private keys and screenshots, and exfiltrates data via the Tor network (ugate.exe). Infection occurs through malicious .LNK files on removable drives and staged payloads from .onion addresses; the malware persists with scheduled tasks, replicates to newly connected USB devices, supports remote code execution, and exhibits behavioral IOCs including unexpected launches of wscript.exe/cscript.exe, curl, PowerShell, cmd.exe, and Tor proxy activity on localhost:9050.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
