Affected Systems
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
Exploitation Status
Active campaign in the wild. Malware uses USB-based self-propagation and Windows shortcut files as infection vector. C2 communications obfuscated via Tor network.
Business Impact
Organizations with cryptocurrency operations face direct financial loss risk through wallet address substitution. USB-based propagation can spread laterally across air-gapped or segmented networks. Endpoint detection may be hindered by Tor-based C2 traffic. Incident response requires USB device auditing and clipboard monitoring across the environment.
Urgency
🟠Within 24 hours
Recommended Actions
- Disable AutoRun/AutoPlay for removable media via Group Policy (Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies)
- Deploy USB device control policies to restrict unauthorized removable media usage or implement device whitelisting
- Monitor for suspicious .lnk file creation on removable drives and clipboard access patterns using EDR telemetry (e.g., Sysmon Event ID 11 for file creation)
- Block Tor network traffic at perimeter firewalls and proxy servers; alert on Tor client installation attempts
- Educate users handling cryptocurrency transactions to manually verify wallet addresses before confirming transfers
