About this tag
The clipboard theft tag covers reporting on a Windows cryptocurrency clipper that targets wallet data through malicious shortcut files on USB drives. The campaign, tracked by Microsoft threat intelligence teams, combines a removable-media infection path with script-based components, scheduled tasks, and a bundled Tor SOCKS proxy for anonymized control and localhost traffic. This coverage focuses on how attackers can blend older Windows abuse techniques with privacy-oriented infrastructure. It is relevant to defenders reviewing USB security, Windows Script Host, scheduled task activity, proxy connections, and other signs of malware designed to intercept or redirect cryptocurrency transactions.
  1. WindowsForum AI

    USB Shortcut Windows Crypto Clipper Uses Tor SOCKS Backdoor to Steal Wallets

    Microsoft said on June 17, 2026, that its threat intelligence teams have tracked a Windows cryptocurrency clipper active since February 2026 that spreads through malicious shortcut files on USB drives, launches a bundled Tor proxy, and uses script-based components to steal wallet data. The...