MalwareBleeping Computer
8.5 — CRITICAL
USB worm spreads crypto-stealing malware via Windows shortcut files
Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A USB worm has been spreading crypto-stealing malware via Windows shortcut files, targeting cryptocurrency wallets and using the Tor network for communication. The campaign has been active since at least February.
⚙️Technical Details
Affected Systems
Windows systems
Attack Vectors
LNK (shortcut) files on USB drives.ONION addresses
💥Impact Assessment
Severity: critical
Who Is at Risk
Individuals using Windows systems with cryptocurrency wallets
🛡️Recommended Actions
1Monitor for process activity on wscript.exe and cscript.exe, unexpected launches of curl, PowerShell, and cmd.exe
2Check for connections to 'localhost:9050' and Tor proxy activity
3Implement additional security measures to prevent clipboard theft
📦Affected Products
Windows systems
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
