Microsoft discovers new lightweight backdoor that steals cryptocurrency



Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.

A lightweight backdoor

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

Microsoft said it observed Crypto Clipper spreading through .lnk file on a USB drive. These files store executable code. When an infected USB drive is plugged into a device, the code checks whether it is already installed on the machine. If it isn’t, the malware downloads it through the Tor proxy. To better conceal evidence of the worm, the malware scans the infected USB drive and names the .lnk files with similar names.



Source link

  • Related Posts

    Today’s NYT Connections Hints, Answers for June 22 #1107

    Looking for the most recent Connections answers? Click here for today’s Connections hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle, Connections:…

    Today’s NYT Wordle Hints, Answer and Help for June 22 #1829

    Looking for the most recent Wordle answer? Click here for today’s Wordle hints, as well as our daily answers and hints for The New York Times Mini Crossword, Connections, Connections: Sports…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Feds’ AI bill good ‘first step’ but safety advocates say more work needed – National

    Feds’ AI bill good ‘first step’ but safety advocates say more work needed – National

    Mbappé: “Lionel Messi es el mejor del mundo junto a Cristiano Ronaldo”

    Mbappé: “Lionel Messi es el mejor del mundo junto a Cristiano Ronaldo”

    Pilot reports passenger bit a fellow flyer on plane approaching Philadelphia: “He’s trying to fight everybody”

    Pilot reports passenger bit a fellow flyer on plane approaching Philadelphia: “He’s trying to fight everybody”

    Fuel sales halted in occupied Crimea as Ukraine targets oil facilities

    Fuel sales halted in occupied Crimea as Ukraine targets oil facilities

    Nathan Saliba obvious next man up to replace Ismaël Koné in decisive Group B match against Switzerland

    Nathan Saliba obvious next man up to replace Ismaël Koné in decisive Group B match against Switzerland

    Ben Stokes: The questions facing England and their captain after difficult fortnight

    Ben Stokes: The questions facing England and their captain after difficult fortnight