bleepingcomputer.com
USB worm spreads crypto-stealing malware via Windows shortcut files
A USB worm is spreading crypto-stealing malware via Windows shortcut files, targeting cryptocurrency wallets since at least February. The malware monitors clipboard contents, replacing wallet addresses with ones controlled by the attacker, and captures screenshots. Infection occurs when a victim opens a malicious LNK file on a USB drive, triggering the malware to execute and spread to other connected devices. The malware uses the Tor network to conceal communication and can capture seed phrases and private keys. [...]