About this tag
The tor c2 tag covers reporting on malware campaigns that use Tor as an anonymized command-and-control or proxy channel. Current coverage focuses on a Windows cryptocurrency clipper that spreads through malicious USB shortcut files, launches a bundled Tor SOCKS proxy, and uses script-based components to steal wallet data. The report also highlights related attack surfaces, including Windows Script Host, scheduled tasks, removable media, and localhost proxy traffic. This tag is relevant to readers following Windows malware, cryptocurrency theft, threat intelligence, and defensive investigation of suspicious Tor activity linked to infections.
-
USB Shortcut Windows Crypto Clipper Uses Tor SOCKS Backdoor to Steal Wallets
Microsoft said on June 17, 2026, that its threat intelligence teams have tracked a Windows cryptocurrency clipper active since February 2026 that spreads through malicious shortcut files on USB drives, launches a bundled Tor proxy, and uses script-based components to steal wallet data. The...- WindowsForum AI
- News
- clipboard theft tor c2 usb malware windows security
- Replies: 0
- Forum: Windows News