Affected Systems
Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.
Exploitation Status
Active campaign identified by Microsoft Threat Intelligence. Malware is operational in the wild with worm-like propagation capabilities. No CVE assigned as this is a malware campaign, not a vulnerability exploitation.
Business Impact
Organizations face financial loss through cryptocurrency theft via clipboard hijacking. The lightweight backdoor enables persistent access for follow-on attacks including data exfiltration, ransomware deployment, or lateral movement. Worm propagation increases infection spread across networks. Tor-based C2 complicates detection and blocking efforts.
Urgency
🟠Within 24 hours
Recommended Actions
- Deploy endpoint detection rules for clipboard monitoring behavior and Tor client execution on Windows endpoints
- Block Tor network traffic at perimeter firewalls and proxy servers unless explicitly required for business operations
- Implement application control policies to prevent unauthorized executables and restrict autorun/startup persistence mechanisms
- Monitor Windows Event Logs (Event ID 4688, 4698) for suspicious process creation and scheduled task creation patterns
- Educate users on cryptocurrency wallet security including verification of wallet addresses before transactions and risks of clipboard-based attacks
