Skip to content
Advertisement
When Appliance Fail?

Microsoft discovers new lightweight backdoor that steals cryptocurrency

Crypto Clipper spreads over USB and communicates over Tor.

schedule 23:28 visibility 4 views
Microsoft discovers new lightweight backdoor that steals cryptocurrency
Source: Ars Technica

Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination.

A lightweight backdoor

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”

Read full article

Comments

newspaper

Originally published at

Ars Technica

open_in_new Read Full Article

Related Articles

Google Calendar finally has more color options for events
Crypto

Google Calendar finally has more color options for events

Running out of color options for events in Google Calendar shouldn't be an issue going forward. The previous limit of 11 predefined colors has now been expanded to give users access to up to 200 custom colors for individual events across the native...

The Verge

Read More

Long Island serial killer sentenced to life in prison
Crypto

Long Island serial killer sentenced to life in prison

A chilling mystery that haunted New York for more than a decade has finally reached a definitive end. On June 17, a Long Island architect was sentenced to life in prison without parole for a horrifying string of serial killings. The "Gilgo Killer"...

France 24
Kürşad Zorlu: Hedefimiz Ortak Dil Platformu'nun kurulması
Crypto

Kürşad Zorlu: Hedefimiz Ortak Dil Platformu'nun kurulması

AK Parti Genel Başkan Yardımcısı, Türk Devletleri ile İlişkiler Başkanı Kürşad Zorlu, "Ortak Türk Alfabesi'nin kullanımı Türk dünyası içerisindeki kültürel ve insani bağların güçlendirilmesi, Türk halklarının ortak dil mirasının korunması ve gelecek...

TRT Haber
Iran's hardliners fear being sidelined in US deal
Crypto

Iran's hardliners fear being sidelined in US deal

As an Iran-US memorandum aimed at ending the war moves closer to formal signature, hardline supporters of the Islamic Republic fear losing influence as Iran's politics shift from maximalist defiance to compromise.

DW News
Your Appliance Broke?
Reliable Repair for