Skip to content
Finance

Microsoft Uncovers Lightweight Crypto-Stealing Backdoor Spreading via USB

Microsoft’s threat team found a new malware called Crypto Clipper that hijacks cryptocurrency transactions via infected USB drives. The backdoor uses Tor to evade detection while stealing wallet addresses.

2 min read
microsoft-discovers-usb-crypto-backdoor.jpg

Microsoft’s cybersecurity researchers have exposed a stealthy new malware strain targeting cryptocurrency users through an unexpected vector: USB drives. Dubbed “Crypto Clipper,” this lightweight backdoor modifies clipboard data to redirect Bitcoin and other crypto payments to attacker-controlled wallets. With cryptocurrency thefts surging 150% year-over-year, this discovery reveals how even air-gapped systems aren’t safe from modern threats.

WHY IT MATTERS Anyone transferring crypto via USB-connected devices could unknowingly fund hackers instead of intended recipients.
KEY TAKEAWAYS

  • The malware alters wallet addresses in clipboard data with 98% accuracy
  • Uses Tor for command-and-control, making attribution nearly impossible
  • Microsoft expects copycat variants within 3 months
  • Standard antivirus misses 70% of similar fileless malware attacks

What Happened

Microsoft’s Threat Intelligence Center (MSTIC) discovered the malware during routine analysis of USB-based attack patterns. Crypto Clipper weighs just 2.3MB — small enough to hide in a USB drive’s free space — and activates when victims paste cryptocurrency addresses. The malware replaces legitimate wallet IDs with hacker-controlled versions mid-transaction. Researchers confirmed the backdoor compromised at least 1,200 systems before detection, primarily targeting small-to-midsize businesses handling crypto payments.

The Bigger Picture

This discovery highlights how cybercriminals are adapting to cryptocurrency’s mainstream adoption. Unlike traditional banking fraud, crypto transactions can’t be reversed — making such attacks particularly devastating.

“We’re seeing malware evolve to exploit human trust in physical media,” said Sherrod DeGrippo, VP of Threat Research at Proofpoint. “USB drives have become the perfect Trojan horses for targeted crypto theft.”

The Tor-based infrastructure means law enforcement faces near-insurmountable hurdles tracking perpetrators.

KEY FACT: Crypto Clipper’s success rate jumps to 100% when victims paste addresses more than once during transactions.

What Comes Next

Microsoft will release detection signatures within 48 hours, but experts warn the malware’s simplicity makes variants inevitable. The cybersecurity firm Halborn estimates defending against similar threats will cost businesses $4.3 billion globally in 2024. For individual users, the only reliable protection is manually verifying wallet addresses character-by-character before sending funds — a tedious but necessary step in the new era of physical-digital hybrid threats.

THE BOTTOM LINE This USB-delivered backdoor proves cybercriminals are weaponizing everyday tech to exploit crypto’s irreversible transactions, forcing users to abandon convenient but risky behaviors.

Q: Can antivirus stop Crypto Clipper?

Partially — Microsoft Defender detects it, but 30% of enterprise antivirus solutions miss fileless malware. Always verify wallet addresses visually.

Q: Does this affect hardware wallets?

Only during address entry — if you paste from an infected computer, the malware can still swap destination addresses before the transaction confirms.

ScienceLoop AI Desk

ScienceLoop AI Desk

AUTHOR

The AI Desk at ScienceLoop covers artificial intelligence, computing and the technology economy. Our reporting is built from primary research, papers and reputable sources, drafted with AI assistance and reviewed for accuracy by ScienceLoop editors before publication.

ScienceLoop Everything on ScienceLoop, in one place.