Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
ID: a76c0dd3-e09b-51e7-8fb1-1c93abce3c59
STIX ID: report--a76c0dd3-e09b-51e7-8fb1-1c93abce3c59
Feed Name: The Hacker News
Microsoft disclosed an active Windows clipper campaign (since Feb 2026) that spreads via malicious LNK files on USB drives, deploys a worm and a clipboard-stealer using WScript/ActiveX, launches a portable Tor client to communicate with a hidden-service C2, performs high-frequency clipboard theft and wallet-address substitution, exfiltrates screenshots, and can execute remote code. Defenders are advised to prioritize behavioral detections (script engines, clipboard/screen-capture actions), disable AutoRun, block LNK execution from removable media, and restrict wscript/cscript usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
