:

USB WORM SPREADS CRYPTO-STEALING MALWARE

SECURITY DESK1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Threat actors are distributing a self-spreading USB worm that steals cryptocurrency wallet data via Windows shortcut files. The malware uses the Tor network to hide command-and-control communications.

The malware operates as a clipboard-stealing trojan with self-propagation capabilities, spreading through removable USB drives. When infected shortcut files (.lnk) are executed, the worm establishes hidden connections through Tor to exfiltrate cryptocurrency wallet credentials and clipboard contents. The attack targets users storing digital assets on infected systems or accessing wallets through web browsers. The self-spreading mechanism allows the malware to propagate to connected USB devices, creating a secondary infection vector for air-gapped systems. The use of Windows shortcut files exploits user trust in familiar file types. Combined with Tor routing, the infrastructure makes attribution and traffic analysis difficult for security researchers. Security researchers recommend disabling autorun features for USB devices, monitoring clipboard activity, and implementing application whitelisting. Users should avoid executing unfamiliar files from removable media and maintain offline backups of cryptocurrency wallet private keys.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.

1H AGOIndustry Desk

Flock Safety, the traffic camera company, is expanding beyond law enforcement with plans to deploy dashcams in rideshare vehicles and offer coaching services to police departments.

1H AGOIndustry Desk

A sharp rise in explicit deepfake images of UK children has been reported by an online safety service, as authorities warn that AI tools are making the creation of sexualized or 'nudified' content increasingly accessible.

1H AGOIndustry Desk

Gen's latest threat report details two distinct attack campaigns exploiting compromised email accounts and clipboard manipulation to steal from businesses and cryptocurrency users.

2H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.