Affected Systems

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Exploitation Status

Active campaign confirmed by Microsoft. Malware propagates via USB devices using LNK files, leveraging Windows Script Host and ActiveX for execution. Tor-based C2 infrastructure in use.

Business Impact

Cryptocurrency theft via clipboard hijacking. USB worm propagation creates lateral movement risk across air-gapped or segmented networks. Tor C2 complicates network-based detection and blocking. Organizations with cryptocurrency operations or USB device usage face direct financial loss risk.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Block Windows Script Host (wscript.exe, cscript.exe) via Group Policy or application control where not required for business operations
  • Disable AutoRun/AutoPlay for removable media via GPO (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun)
  • Monitor for LNK file creation on USB devices and execution of scripts from removable media using EDR or Sysmon Event ID 1 (process creation) with command-line logging
  • Block Tor network connections at perimeter firewalls and proxy infrastructure; alert on tor.exe or Tor Browser execution
  • Educate users on cryptocurrency clipboard hijacking behavior and verify wallet addresses before confirming transactions