Microsoft flags USB malware that swaps crypto addresses
Microsoft warns of USB-spread malware that swaps copied crypto addresses, steals 12- and 24-word seed phrases and replaces files with .lnk shortcut files.
Microsoft has issued an alert about a malware strain that spreads via USB drives, replaces files with Windows shortcut (.lnk) files and alters copied cryptocurrency addresses to attacker-controlled values. The company reported the activity after analysis by the Microsoft Defender team.
According to Microsoft, the malware propagates by replacing files on removable media with shortcut files that, when opened, execute the infection and copy the malicious code onto any USB drive connected to a compromised PC. The shortcuts are the main vector used to move the program between machines.
Researchers described the program as script-based and running continuously on infected devices. The malware includes measures to avoid deletion or detection by security tools and uses Tor-based anonymized communications to hide its network activity.
The malware monitors system memory and the clipboard for what Microsoft calls “high-value financial artifacts.” It searches for 12- and 24-word BIP39 seed phrases pasted into the clipboard and exfiltrates them to attackers, along with up to five screenshots that show wallet context and balances. A clipper component scans memory every 500 milliseconds for cryptocurrency addresses including Bitcoin, Tron and Monero and replaces any detected address with a similar one controlled by the attackers.
To reduce the risk of infection, Microsoft recommended disabling autorun for removable media and blocking execution of shortcut files from external drives. The company also advised keeping endpoint protection up to date so detection and removal capabilities cover the script-based components.
Microsoft Defender researchers wrote in their alert: “This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking.” The alert includes technical details of the propagation and monitoring routines.
BIP39 seed phrases are 12- or 24-word master keys used by many cryptocurrency wallets; anyone who obtains a seed phrase can recreate the wallet and move its funds. Clipboard clippers have been used in previous campaigns to replace pasted addresses and siphon transfers; Microsoft’s report notes this variant adds seed theft and screenshot capture, increasing the types of data attackers can harvest.
Microsoft urged users and administrators to apply the recommended mitigations and to review removable media handling policies to limit exposure to the shortcut-based propagation method.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








