Find notable cyber news and cases, enriched with sources, timelines, and signals.

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds clipboard theft, screenshot exfiltration, and wallet-address substitution, increasing the risk of stolen seed phrases and diverted transactions. It also uses a Tor-based hidden-service C2 and can execute attacker-supplied code through an EVAL response.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...

ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion

Technical Analysis
H score74 First: 01.07.2026 08:32 Last: 01.07.2026 08:32 Sources 1

About this happening: Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...

TonRAT Node.js implant with TON blockchain C2

Malware Activity
H score24 First: 26.06.2026 12:27 Last: 26.06.2026 12:27 Sources 1

About this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...

Amadey and StealC MaaS ecosystem and affiliate model

Threat Actor Meta
H score73 First: 24.06.2026 18:59 Last: 24.06.2026 18:59 Sources 1

About this happening: The Amadey and StealC ecosystems now operate as malware-as-a-service (MaaS) offerings, widening access to loader and stealer capabilities for paying customers and affi...

Amadey and StealC shared-infrastructure malware activity

Malware Activity
H score66 First: 24.06.2026 18:02 Last: 24.06.2026 18:02 Sources 1

About this happening: The Amadey loader and StealC infostealer are being linked through shared C&C infrastructure, making the pair easier to coordinate and disrupt. Amadey helps attacke...

Timeline

  1. 18.06.2026 17:30 2 articles · 27d ago

    Windows cryptocurrency clipper campaign uses USB LNK worm and Tor C2

    Initial Disclosure

    Microsoft disclosed a Windows-based cryptocurrency clipper campaign targeting cryptocurrency users on Windows systems since February 2026. The malware uses malicious USB-delivered Windows Shortcut (LNK) files, Windows Script Host and ActiveX-driven logic, a portable Tor client with a local SOCKS5 proxy, and a hidden-service C2 server to steal clipboard data, replace wallet addresses, exfiltrate screenshots, and execute attacker-supplied code when the C2 returns an EVAL response.

    Show sources