Affected Systems

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

Exploitation Status

Active campaign in the wild. Malware uses USB-based self-propagation and Windows shortcut files as infection vector. C2 communications obfuscated via Tor network.

Business Impact

Organizations with cryptocurrency operations face direct financial loss risk through wallet address substitution. USB-based propagation can spread laterally across air-gapped or segmented networks. Endpoint detection may be hindered by Tor-based C2 traffic. Incident response requires USB device auditing and clipboard monitoring across the environment.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Disable AutoRun/AutoPlay for removable media via Group Policy (Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies)
  • Deploy USB device control policies to restrict unauthorized removable media usage or implement device whitelisting
  • Monitor for suspicious .lnk file creation on removable drives and clipboard access patterns using EDR telemetry (e.g., Sysmon Event ID 11 for file creation)
  • Block Tor network traffic at perimeter firewalls and proxy servers; alert on Tor client installation attempts
  • Educate users handling cryptocurrency transactions to manually verify wallet addresses before confirming transfers