Microsoft discovers new lightweight backdoor that steals cryptocurrency
Crypto Clipper spreads over USB and communicates over Tor.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers. The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination. A lightweight backdoor “The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”Read full article Comments
Stay on the signal
Follow Microsoft discovers new lightweight backdoor that steals cryptocurrency
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
3
Related articles
More stories that share tags, source, or category context.
Прячется на флешке и боится диспетчера задач. Microsoft раскрыла хитрую программу, похищающую крипту
Достаточно было открыть привычный ярлык, чтобы сценарий пошёл не по плану.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Microsoft new Outlook takes 10 seconds to do what Outlook Classic does instantly
Comments
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Исправления нет, эксплойт есть. Microsoft оставила пользователей Windows наедине с 0Day в Защитнике
Microsoft: «Мы изучаем проблему»...Прошла неделя...Microsoft: «Ладно, признаём».
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
«Ничего подозрительного, просто Teams». Хакеры спрятали управление вирусом за обычной рабочей перепиской
Обнаружен первый случай использования инфраструктуры Microsoft Teams для сокрытия управления вредоносным ПО.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
A bold satellite rescue mission came together in record time, but will it work?
"I consider this a success already, just from the fact that we're even going to try this."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
FDA advisors unanimously vote to approve Moderna's mRNA after agency drama
In February, a Trump official refused to review the vaccine.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
As China looms, Taiwan makes more drones for defense and the US military
Taiwan's drone spending plans for defense could also boost business overseas.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
NASA asks Northrop Grumman to stop working on lunar HALO module
"We are reassigning most affected employees across existing opportunities and programs."
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.