Affected Systems
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
Exploitation Status
Active campaign confirmed by Microsoft. Malware propagates via USB devices using LNK files, leveraging Windows Script Host and ActiveX for execution. Tor-based C2 infrastructure in use.
Business Impact
Cryptocurrency theft via clipboard hijacking. USB worm propagation creates lateral movement risk across air-gapped or segmented networks. Tor C2 complicates network-based detection and blocking. Organizations with cryptocurrency operations or USB device usage face direct financial loss risk.
Urgency
🟠Within 24 hours
Recommended Actions
- Block Windows Script Host (wscript.exe, cscript.exe) via Group Policy or application control where not required for business operations
- Disable AutoRun/AutoPlay for removable media via GPO (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun)
- Monitor for LNK file creation on USB devices and execution of scripts from removable media using EDR or Sysmon Event ID 1 (process creation) with command-line logging
- Block Tor network connections at perimeter firewalls and proxy infrastructure; alert on tor.exe or Tor Browser execution
- Educate users on cryptocurrency clipboard hijacking behavior and verify wallet addresses before confirming transactions
