# USB Worm Spreads Crypto-Stealing Malware Through Windows Shortcuts—A Growing Threat to Wallet Holders


A sophisticated worm campaign targeting cryptocurrency users has been quietly operating since at least February 2026, using infected USB drives and deceptive Windows shortcut files to deploy clipboard-stealing malware capable of draining digital wallets. Microsoft security researchers have documented the campaign's self-propagating mechanisms, Tor-based command infrastructure, and multi-layered data theft capabilities, raising alarms among security professionals about the intersection of physical media attacks and cryptocurrency fraud.


## The Threat


Campaign Overview


Threat actors behind this operation have weaponized an age-old attack vector—removable storage devices—to distribute modern cryptocurrency theft malware. The campaign demonstrates how attackers continue to exploit the gap between user expectations about USB drives and the actual risks they pose. Unlike email-based phishing or web exploits, USB worm infections require minimal technical sophistication from victims; users need only open a file that appears to be a document.


Attack Scope


The worm specifically targets users holding significant cryptocurrency assets across multiple blockchain networks, including:

  • Bitcoin (legacy, P2SH, Bech32, and Taproot addresses)
  • Ethereum
  • Tron
  • Monero

  • The malware's focus on seed phrases and private keys—the cryptographic materials that grant complete control over wallets—indicates attackers are seeking long-term access to victim assets rather than one-time theft.


    ## How It Works: Technical Breakdown


    Initial Infection Vector


    The attack begins when a victim connects an infected USB drive to their Windows system and opens a .LNK (shortcut) file, often disguised with legitimate-looking names. These shortcut files are Windows' native linking mechanism and are frequently trusted by users who believe they're harmless references to actual files.


    Upon execution, the shortcut triggers malware stored on the USB drive. Rather than containing the legitimate file the shortcut claims to reference, it launches malicious code that establishes persistence and begins preparing additional payloads staged from a .onion Tor network address.


    Worm Propagation Mechanism


    Once installed, the malware implements an intelligent propagation strategy:


    1. Document Discovery: A local scan searches the infected system for document files (PDFs, Word files, spreadsheets, etc.)

    2. Substitution: The malware hides original documents and replaces them with malicious shortcut files bearing identical names and icons

    3. Execution on Access: When users attempt to open what they believe are legitimate documents, the malware executes instead

    4. USB Monitoring: A scheduled task continuously monitors for newly connected USB storage devices, automatically copying itself and creating malicious shortcuts on any detected removable media


    This multi-pronged approach ensures both persistent infection across the local system and rapid spread to other devices that users connect to the infected machine.


    Data Exfiltration Component


    The stealer module operates through a methodical process:


    | Function | Frequency | Target Data |

    |----------|-----------|-------------|

    | Clipboard Monitoring | Every 500ms | Seed phrases, private keys, wallet addresses |

    | Screenshot Capture | Every 10 seconds | Five screenshots per interval |

    | Address Validation | Real-time | Checks for 12/24-word seed phrases and crypto keys |


    The malware specifically monitors clipboard contents for:

  • 12-word BIP39 seed phrases (commonly used in hardware wallets)
  • 24-word BIP39 seed phrases (higher-security variant)
  • Ethereum private keys
  • Bitcoin Wallet Import Format (WIF) keys
  • Tron wallet identifiers
  • Monero wallet data

  • Address Substitution Strategy


    Rather than replacing addresses with obviously fraudulent ones, the malware employs sophisticated obfuscation: it targets cryptocurrency addresses that partially resemble the attackers' own wallet addresses based on starting digits or characters. This minimal-change approach reduces the likelihood that users will notice discrepancies at a glance—a critical factor since many users copy-paste addresses rather than verifying them character-by-character.


    Command and Control Infrastructure


    Communications with attacker-controlled servers occur through Tor, masking the malware's true command infrastructure. The malware runs a Tor executable (ugate.exe) to anonymize outbound connections. Beyond data exfiltration, the C2 infrastructure supports remote code execution: attackers can send an EVAL instruction causing the malware to download JavaScript code, save it to a file called 'cfile,' and execute it on the compromised machine. This capability transforms infected systems into remotely controlled agents capable of executing arbitrary attacker commands.


    ## Background and Context


    The Persistent Appeal of Physical Media Attacks


    While enterprise security has shifted heavily toward defending against network-based threats, USB-based attacks remain effective because they exploit genuine constraints in modern security architecture. USB devices occupy a unique position in the threat landscape:


  • Trust gap: Users generally perceive USB drives as less risky than email attachments
  • Bypass opportunity: USB malware can evade email filters and network monitoring
  • Physical access exploitation: Corporate networks with restricted USB policies create opportunities for targeted attacks against high-value individuals
  • Document deception: Shortcut file attacks abuse the expectation that .LNK files are harmless navigation aids

  • The cryptocurrency angle adds economic incentive. Unlike traditional malware that may target credentials or identity information with uncertain resale value, cryptocurrency theft directly yields liquid digital assets that attackers can exchange for fiat currency through crypto exchanges.


    Evolution of Cryptocurrency-Targeting Malware


    This campaign fits within a broader trend of malware evolution targeting digital assets. Previous campaigns like TrickMo (which adopted blockchain-based communications), Miasma (which distributed as worm source code), and TCLBanker (which self-spread over messaging platforms) demonstrate that cryptocurrency theft remains one of the most lucrative motivations for malware development.


    ## Detection and Response Indicators


    Behavioral Indicators


    Microsoft researchers emphasize that behavioral detection should be the primary defense mechanism, as signature-based detection is easily bypassed through minor malware variants.


    Organizations should establish monitoring alerts for:


  • Process Execution
  • - Unexpected launches of wscript.exe or cscript.exe (Windows script hosts)

    - Suspicious invocations of curl (often used for data exfiltration)

    - Unusual PowerShell or cmd.exe process launches

    - Execution from temporary directories or USB paths


  • Network Activity
  • - Connections to localhost:9050 (Tor SOCKS proxy port)

    - Tor client process execution

    - Connections to suspicious .onion addresses


  • System Monitoring
  • - Unexpected scheduled task creation

    - Rapid file access patterns across document libraries

    - USB device monitoring or copying activities


    Defense Prioritization


    Detection effectiveness varies significantly by organizational maturity. Security teams currently identify only 54% of successful attacks and alert on just 14%—meaning the remaining attacks move through environments undetected. This statistic underscores the importance of layer-based defense strategies rather than reliance on any single detection mechanism.


    ## Implications for Cryptocurrency Users and Organizations


    Individual Risk


    Cryptocurrency holders face direct financial exposure. Unlike traditional fraud where stolen credentials may be locked down before full account compromise, stolen seed phrases or private keys grant permanent access to cryptocurrency wallets. Users typically cannot recover or reset these credentials through normal account recovery procedures.


    Organizational Risk


    Organizations with employees who hold cryptocurrency face secondary exposure:

  • Ransomware vectors: Compromised systems become staging grounds for enterprise attacks
  • Credential theft: The malware's screenshot capability captures sensitive information beyond cryptocurrency data
  • Insider threat escalation: Compromised employees may have network access to corporate resources

  • Supply Chain Concerns


    The worm's USB propagation mechanism means that organizational procurement, testing, and data transfer processes become potential infection vectors. Shared USB devices (for documentation, firmware, or data transfer) within corporate environments could distribute the malware across multiple machines.


    ## Recommendations


    For Cryptocurrency Users


  • Hardware wallet adoption: Store cryptocurrency on dedicated hardware wallets that never expose private keys to internet-connected computers
  • Air-gapped verification: Verify cryptocurrency addresses on a separate, unconnected device before sending funds
  • USB vigilance: Treat USB drives with extreme caution; only use those from trusted sources and consider treating external USB connections as potential infection points
  • Clipboard isolation: For high-value transactions, manually transcribe addresses rather than copy-pasting to reduce clipboard monitoring risk

  • For Organizations


  • USB restrictions: Enforce technical controls preventing USB drives from executing code; consider blocking USB storage on sensitive workstations
  • Behavioral monitoring: Deploy EDR (Endpoint Detection and Response) solutions that alert on suspicious process execution chains, particularly involving script hosts and curl
  • Task scheduling monitoring: Alert on unexpected scheduled task creation, especially from user-writable paths
  • Network segmentation: Isolate cryptocurrency infrastructure and users from general corporate networks where possible
  • Incident response: Develop playbooks for cryptocurrency wallet compromise including immediate wallet migration and blockchain transaction forensics

  • For System Administrators


  • Monitor for .LNK file creation patterns across document directories
  • Implement AppLocker or Windows Defender Application Control policies restricting script execution
  • Block Tor client execution through host-based firewall rules
  • Configure USB device monitoring and restrict USB automount capabilities

  • ---


    ## HackWire Analysis


    Why This Campaign Matters Now


    This campaign arrives at a critical inflection point in cryptocurrency security. As Bitcoin and Ethereum reach mainstream adoption—with institutional investors, corporate treasuries, and even nation-states holding significant positions—the attack surface has broadened dramatically. The sophistication lies not in exotic exploitation techniques but in exploiting the widening gap between user awareness of blockchain technology and user discipline around cybersecurity fundamentals.


    The timing is significant because USB worm campaigns fundamentally challenge the security assumptions of users who believe they've "solved" cryptocurrency security through hardware wallets. Even airgapped hardware wallet users remain vulnerable: they must interact with internet-connected systems to initiate transactions, review addresses, and confirm transfers. This campaign targets exactly that interaction point.


    Pattern Recognition: The Physical Media Renaissance


    We're witnessing a broader resurgence in physically-mediated attacks. While security discourse focuses almost exclusively on network-based threats, threat actors continue exploiting the reality that physical access—or the perception of physical trust—remains highly effective. This worm joins recent supply-chain attacks (npm package injection, GitHub source code leaks) in exploiting the fragile trust in data transfer mechanisms. The common thread: users trust the medium more than they verify the content.


    The Hidden Risk: Tor-Based Botnet Infrastructure


    Most reporting on this campaign focuses on the clipboard-stealing mechanics, but the most concerning element is the command infrastructure. The malware's ability to download and execute arbitrary JavaScript through Tor-based C2 means compromised systems become remotely controllable nodes. Attackers can evolve capabilities, shift targets (from cryptocurrency to corporate espionage), or rent out infected machines as botnet resources—long after the initial infection. Organizations identifying this malware should assume complete system compromise, not just data theft.


    Defender Action Item: Organizations should implement detection for Tor client execution regardless of cryptocurrency exposure, as Tor activity is an almost-universal indicator of compromise in corporate environments.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Breaches](https://www.hackwire.news/category/breaches)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)