:

MICROSOFT WARNS OF CRYPTO-STEALING BACKDOOR

INDUSTRY DESK2 MIN READ
FRI, JUN 19, 2026

■ AI-SUMMARIZED FROM 3 SOURCES ▸ TIMELINE

Microsoft has identified a lightweight backdoor malware that targets cryptocurrency wallets and spreads via USB drives. The malware, known as Crypto Clipper, communicates through the Tor network to evade detection.

Microsoft's security team discovered the backdoor during routine threat analysis. The malware operates with minimal system footprint, making it difficult to detect through conventional security tools. ■ Infection Method Crypto Clipper spreads primarily through infected USB devices. When connected to a target system, the malware executes automatically, establishing persistence on the host machine. This distribution method proves particularly effective in corporate and high-value environments where USB transfers remain common. ■ Technical Details The malware targets cryptocurrency wallet applications and clipboard data. It monitors clipboard activity to intercept wallet addresses when users copy them during transactions. When a cryptocurrency transfer is detected, Crypto Clipper substitutes the legitimate wallet address with an attacker-controlled address, redirecting funds. Communication occurs over the Tor network, which anonymizes command-and-control traffic and complicates tracking and attribution. This infrastructure choice indicates a sophisticated threat actor with operational security awareness. ■ Scope and Impact Microsoft has identified Crypto Clipper activity across multiple regions, though specific target organizations remain undisclosed. The lightweight nature of the malware allows it to evade traditional antivirus solutions, increasing its effectiveness. ■ Recommendations Microsoft advises users to: - Disable AutoPlay for USB devices - Verify cryptocurrency addresses through secondary channels before confirming transactions - Implement application whitelisting on systems handling sensitive cryptocurrency operations - Update security software and operating systems regularly - Monitor systems for unexpected network connections to Tor exit nodes The discovery underscores ongoing threats to cryptocurrency users and the continued evolution of financially motivated malware. Organizations should review USB device policies and consider restricting external media on systems with financial access.

■ SOURCES

Ars TechnicaBleeping ComputerBloomberg Tech

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A proof-of-concept attack called BragJack can hijack AI assistants across multiple browsers and platforms through a single malicious extension. Security researcher Gal Weizman from Forever Security demonstrated the vulnerability using a Prompt Forcing technique.

JUST NOWAI Desk

Law enforcement agencies have issued a joint advisory detailing a sustained campaign by the North Korean hacking group WaterPlum, which compromised at least 30,000 devices worldwide and stole over $10.7 million in cryptocurrency between December 2025 and July 2026.

1H AGOSecurity Desk

If your PC is running slowly or behaving unusually, malware may be the culprit. Running a malware check is a straightforward way to diagnose and address the problem.

1H AGOSecurity Desk

A detailed investigation revealed that smart TVs from major manufacturers collect extensive user data, including audio recordings and viewing habits, even when devices appear powered off. The practice extends across the industry, not limited to LG.

1H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.