Back to all lessons
Awareness Lessons
4 months ago

USB Worm Hijacks Crypto Wallets via Windows Shortcut Files

This attack exploits the tendency of users to trust and plug in USB devices without scrutiny, combined with default Windows configurations that auto-execute shortcut (.lnk) files. The malware silently monitors the clipboard, replacing copied cryptocurrency wallet addresses with attacker-controlled ones — a technique known as clipboard hijacking — meaning victims unknowingly send funds directly to attackers. It further exfiltrates screenshots and hides its command-and-control traffic over Tor, making detection extremely difficult. The combination of physical media as an infection vector and stealthy financial theft highlights how legacy attack methods remain highly effective when security hygiene is weak. Organizations and individuals handling cryptocurrency are at particular risk if endpoint controls and user awareness programs are not kept current.

Tactical Insight

Immediate actions

  • Disable Windows AutoRun/AutoPlay for all removable media via Group Policy to prevent automatic execution of shortcut files.
  • Block or restrict USB storage device usage on endpoints using endpoint security tools or Group Policy Object (GPO) controls.
  • Deploy or update endpoint detection and response (EDR) tools to flag suspicious .lnk file execution and clipboard-manipulation behaviors.

Long-term improvements

  • Establish and enforce a removable media policy that prohibits use of unverified USB devices on corporate or personal cryptocurrency-handling systems.
  • Implement application allowlisting to prevent unauthorized executables dropped from USB devices from running.
  • Segregate cryptocurrency transaction systems onto hardened, isolated machines that have no general internet or USB access.

Detection measures

  • Monitor and alert on clipboard-access API calls from unexpected processes using behavioral analytics or EDR rules.
  • Log and inspect outbound Tor network traffic at the perimeter firewall, blocking Tor exit node IPs and .onion DNS resolution.
  • Conduct regular threat hunting for persistence mechanisms (e.g., scheduled tasks, registry run keys) commonly used by USB worm payloads.