Microsoft Flags New USB Malware Stealing 12/24-Word Seed Phrases From Crypto Users

BTC0.42%
TRX0.48%
According to Microsoft Defender, on June 17, the Windows security team flagged a new USB-based malware that targets cryptocurrency users by stealing BIP39 seed phrases and altering wallet addresses. The malware propagates through removable drives by replacing files with shortcuts (.lnk files), which trigger infection upon execution and establish Tor-powered communication to avoid detection. Once active, it scans memory for 12 or 24-word seed phrases in clipboard data and detects addresses of Bitcoin, Tron, and Monero, replacing them with attacker-controlled addresses to redirect funds. Microsoft recommends disabling autorun for removable media and blocking shortcut execution from USB drives to prevent infection.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments