Microsoft Warns USB-Based Malware Targeting Bitcoin Users

Microsoft has warned Windows users about a malware strain spreading via USB flash drives that hijacks cryptocurrency transactions by replacing copied wallet addresses with those controlled by attackers. The “clipper” malware leverages Windows shortcut files to infect devices, posing a direct risk to anyone transferring digital assets.

Microsoft Flags USB-Spread ‘Clipper’ Malware

According to an alert from the Microsoft Defender team, the malware propagates through removable media by abusing Windows shortcut (.LNK) files. Once active on a system, it monitors the clipboard for cryptocurrency addresses and swaps them with attacker-owned addresses, potentially redirecting funds during a transaction.

How the Attack Works

  • The malware arrives via infected USB drives that contain malicious shortcut files.
  • After execution, it runs in the background and watches the clipboard for strings that resemble cryptocurrency wallet addresses.
  • When a user copies a wallet address to send funds, the malware replaces it with a lookalike address controlled by the attacker.
  • Because most crypto transfers are irreversible, victims may not recover funds sent to the wrong address.

Why It Matters for Crypto Users

Clipboard-hijacking threats are designed to exploit a common step in crypto transactions: copying and pasting addresses. Even careful users can be affected if they fail to verify the full address before confirming a transfer. The use of USB-borne shortcuts increases the risk of cross-device spread, including in shared or corporate environments.

Recommended Precautions

  • Verify the entire destination address before authorizing any crypto transaction.
  • Keep Windows and security software, including Microsoft Defender or equivalent tools, fully updated.
  • Scan all removable media before opening files and avoid running unknown shortcut (.LNK) files.
  • Disable or restrict autorun features for removable drives where possible.
  • Limit the use of untrusted USB devices and maintain regular system and wallet backups.

As malware campaigns continue to target crypto holders, robust device hygiene and meticulous transaction checks remain critical to preventing losses.

×