Microsoft Threat Intelligence reports a new self-propagating malware family that spreads through USB drives to search for cryptocurrency-related data. The malware, identified as “Crypto Clipper,” scans a Windows device’s clipboard for patterns consistent with cryptocurrency wallet addresses and seed phrases. If those indicators are found, it captures them and sends the stolen information to attacker-controlled servers.
Microsoft says the malware also uses screenshot capture, taking several screenshots over a short period to provide additional context. For command-and-control and data exfiltration, the malware is described as using a portable Tor client and routing traffic through a local SOCKS5 proxy rather than relying on exposed IP-based infrastructure. The infection flow involves malicious shortcut (.lnk) files placed on removable media. When an infected USB drive is connected, the code checks whether it is already installed on the host; if not, it downloads and executes payload components.
The reports also describe attempts to hinder analysis or detection, including scanning and renaming .lnk files to resemble legitimate ones. Microsoft further states the malware can replace discovered cryptocurrency addresses with attacker-controlled wallet addresses, redirecting potential payments. Microsoft estimates the campaign has been active since at least February 2026.