logo

USB worm spreads crypto-stealing malware via Windows shortcut files

ID: bd38ed32-769e-5839-a4e9-0d5b8419bc64

STIX ID: report--bd38ed32-769e-5839-a4e9-0d5b8419bc64

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Bill Toulas

...
...

A USB-spreading worm campaign active since at least February distributes a clipboard-stealing 'clipper' that replaces cryptocurrency wallet addresses, captures seed phrases, private keys and screenshots, and exfiltrates data via the Tor network (ugate.exe). Infection occurs through malicious .LNK files on removable drives and staged payloads from .onion addresses; the malware persists with scheduled tasks, replicates to newly connected USB devices, supports remote code execution, and exhibits behavioral IOCs including unexpected launches of wscript.exe/cscript.exe, curl, PowerShell, cmd.exe, and Tor proxy activity on localhost:9050.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.