News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Jun 18, 2026 at 23:28 Big Tech Rising Hot

Microsoft discovers new lightweight backdoor that steals cryptocurrency

Crypto Clipper spreads over USB and communicates over Tor.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Microsoft discovers new lightweight backdoor that steals cryptocurrency

Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers. The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When found, the malware also takes five screenshots over a 10-second period. Both the credentials and the screenshots are then sent to the attacker through Tor, a network protocol that provides anonymous routing by sending traffic through redundant nodes so logs can’t capture both the sending and receiving IP addresses. Crypto Clipper establishes the Tor connection by using a SOCKS5 proxy, a network protocol that sends traffic through a proxy server, which then forwards it to its final destination. A lightweight backdoor “The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”Read full article Comments

Stay on the signal

Follow Microsoft discovers new lightweight backdoor that steals cryptocurrency

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Communicates, Crypto Clipper, and Cryptocurrency, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Jun 18, 2026 at 23:28 Ars Technica

Microsoft discovers new lightweight backdoor that steals cryptocurrency

Crypto Clipper spreads over USB and communicates over Tor.

Jun 18, 2026 at 18:02 SecurityLab

Прячется на флешке и боится диспетчера задач. Microsoft раскрыла хитрую программу, похищающую крипту

Достаточно было открыть привычный ярлык, чтобы сценарий пошёл не по плану.

Jun 18, 2026 at 12:19 Hacker News

Microsoft new Outlook takes 10 seconds to do what Outlook Classic does instantly

Comments

Jun 18, 2026 at 09:06 SecurityLab

Исправления нет, эксплойт есть. Microsoft оставила пользователей Windows наедине с 0Day в Защитнике

Microsoft: «Мы изучаем проблему»...Прошла неделя...Microsoft: «Ладно, признаём».

Jun 18, 2026 at 08:01 SecurityLab

«Ничего подозрительного, просто Teams». Хакеры спрятали управление вирусом за обычной рабочей перепиской

Обнаружен первый случай использования инфраструктуры Microsoft Teams для сокрытия управления вредоносным ПО.

Jun 17, 2026 at 10:44 SecurityLab

1-Click атака: кликнул, Copilot нашёл, Bing доставил. И всё это — через сайты самой Microsoft, которым все доверяли

Уязвимость SearchLeak в Microsoft Copilot позволяла похищать почту и коды подтверждения после перехода по ссылке.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

3

Related articles

More stories that share tags, source, or category context.

SecurityLab Jun 18, 2026 at 18:02 Cybersecurity
Rising Hot

Прячется на флешке и боится диспетчера задач. Microsoft раскрыла хитрую программу, похищающую крипту

Достаточно было открыть привычный ярлык, чтобы сценарий пошёл не по плану.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

SecurityLab Jun 18, 2026 at 09:06 Cybersecurity
Rising Hot

Исправления нет, эксплойт есть. Microsoft оставила пользователей Windows наедине с 0Day в Защитнике

Microsoft: «Мы изучаем проблему»...Прошла неделя...Microsoft: «Ладно, признаём».

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

SecurityLab Jun 18, 2026 at 08:01 Cybersecurity
Rising Hot

«Ничего подозрительного, просто Teams». Хакеры спрятали управление вирусом за обычной рабочей перепиской

Обнаружен первый случай использования инфраструктуры Microsoft Teams для сокрытия управления вредоносным ПО.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page