logo

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

ID: a76c0dd3-e09b-51e7-8fb1-1c93abce3c59

STIX ID: report--a76c0dd3-e09b-51e7-8fb1-1c93abce3c59

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed an active Windows clipper campaign (since Feb 2026) that spreads via malicious LNK files on USB drives, deploys a worm and a clipboard-stealer using WScript/ActiveX, launches a portable Tor client to communicate with a hidden-service C2, performs high-frequency clipboard theft and wallet-address substitution, exfiltrates screenshots, and can execute remote code. Defenders are advised to prioritize behavioral detections (script engines, clipboard/screen-capture actions), disable AutoRun, block LNK execution from removable media, and restrict wscript/cscript usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.