Microsoft says a Windows malware campaign is spreading through USB drives and stealing cryptocurrency by swapping copied wallet addresses with attacker-controlled ones. The malware uses malicious LNK shortcut files to launch from removable media, hides real documents and replaces them with lookalike shortcuts, propagates to newly connected USB devices, and uses Tor for command-and-control. It also looks for seed phrases and private keys, captures screenshots, and supports remote code execution through JavaScript fetched from a .onion address.
Why it matters: This can hit ordinary users and organizations that still share files by USB, especially anyone handling cryptocurrency wallets or recovery phrases. Defenders should watch for suspicious wscript.exe and cscript.exe activity, Tor proxy traffic such as localhost:9050, and unusual shortcut files on removable drives; users should avoid opening unexpected files from USB media and verify wallet addresses carefully.
Bill Toulas
2026.06.18
100% relevant
This article establishes a distinct malware campaign centered on USB-borne LNK worm propagation and cryptocurrency clipboard theft, not a follow-up to an existing tracked story.
← Back to all stories