$ intel.mask2.ca

ADVISORY · 2026-06-18 · SRC MSFT-SECURITY · HIGH
2026-06-18 high REL 6/10

Cryptocurrency Clipper Malware Uses Tor and Worm Propagation for Persistent Control

financeenergypost-secondarygeneral

Microsoft researchers identified a sophisticated cryptocurrency clipper campaign that combines clipboard interception with wallet replacement tactics. The malware establishes persistent backdoor access and spreads using worm-like mechanisms while leveraging Tor for command and control communications.

Why it matters in Western Canada: Financial services, energy sector workers, and post-secondary staff in Western Canada who handle cryptocurrency or digital assets may be targeted by this persistent malware. Organizations managing sensitive financial transactions should implement controls to prevent clipboard-based theft.


Summary generated from the original advisory. Read the full source: msft-security

Source
https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
CVEs
None listed
Tags
cryptocurrency, malware, persistence, clipboard-theft, tor
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)