Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
Summary
Hide ▲
Show ▼
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds clipboard theft, screenshot exfiltration, and wallet-address substitution, increasing the risk of stolen seed phrases and diverted transactions. It also uses a Tor-based hidden-service C2 and can execute attacker-supplied code through an EVAL response.
Related Happenings
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
H score31
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
About this happening:
The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware ActivityAbout this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...
ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion
Technical Analysis
H score74
First: 01.07.2026 08:32
Last: 01.07.2026 08:32
Sources 1
About this happening:
Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...
ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion
Technical AnalysisAbout this happening: Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...
TonRAT Node.js implant with TON blockchain C2
Malware Activity
H score24
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
TonRAT Node.js implant with TON blockchain C2
Malware ActivityAbout this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor Meta
H score73
First: 24.06.2026 18:59
Last: 24.06.2026 18:59
Sources 1
About this happening:
The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Amadey and StealC MaaS ecosystem and affiliate model
Threat Actor MetaAbout this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...
Amadey and StealC shared-infrastructure malware activity
Malware Activity
H score66
First: 24.06.2026 18:02
Last: 24.06.2026 18:02
Sources 1
About this happening:
The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
Amadey and StealC shared-infrastructure malware activity
Malware ActivityAbout this happening: The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...
Timeline
-
18.06.2026 17:30 2 articles · 27d ago
Windows cryptocurrency clipper campaign uses USB LNK worm and Tor C2
Initial DisclosureMicrosoft disclosed a Windows-based cryptocurrency clipper campaign targeting cryptocurrency users on Windows systems since February 2026. The malware uses malicious USB-delivered Windows Shortcut (LNK) files, Windows Script Host and ActiveX-driven logic, a portable Tor client with a local SOCKS5 proxy, and a hidden-service C2 server to steal clipboard data, replace wallet addresses, exfiltrate screenshots, and execute attacker-supplied code when the C2 returns an EVAL response.
Show sources
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 — thehackernews.com — 18.06.2026 17:30
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 — thehackernews.com — 18.06.2026 17:30