Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
Details of a Windows-based cryptocurrency clipper operation that has been targeting victims since February 2026 with clipboard-intercepting malware that may distribute itself and conceal communication over the Tor anonymity network have been revealed by Microsoft.
According to a research released on Tuesday by the Microsoft Defender Security Research Team, the clipper in this campaign uses Windows Script Host and ActiveX-driven logic to start a packaged Tor proxy and poll a hidden-service C2 [command-and-control] server. It does wallet-address substitution, screenshot exfiltration, and high-frequency clipboard stealing.
This clipper's execution is noteworthy because it doesn't rely on exposed IP-based C2 infrastructure or a conventional installation. Rather, it turns a financially m...










