Microsoft Warns USB-Spreading Crypto Clipper Malware Is Hijacking Wallet Transfers
Microsoft Threat Intelligence said cryptocurrency clipper malware is exploiting the Windows clipboard. Because users typically copy and paste wallet addresses, the malware can secretly replace the intended recipient address and divert assets to an attacker’s wallet. The number of victims and the amount stolen have not been disclosed.
The malware has remained active since February and was recently found to spread through USB drives, creating a cross-device infection chain. In addition to altering cryptocurrency wallet addresses stored in the clipboard, it can capture screenshots to steal credentials and serve as a backdoor for executing arbitrary code. Related activity was also covered in a June 23 cybersecurity daily report.
All Coverage
4 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.