傳播途徑包括惡意 .lnk 捷徑檔案透過 USB 隨身碟散播,並可跨越氣隙環境,微軟建議關閉自動播放、封鎖 USB 的 .lnk 執行,並監控 localhost:9050 的 SOCKS5 流量。
What is the CryptoBandits malware campaign disclosed by Microsoft in June 2026, including its clipboard-hijacking mechanism targeting BitcoiConceptual visualization of clipboard hijacking malware intercepting a cryptocurrency transaction. Source: AI-generated editorial image.
AI 提示詞
Create a landscape editorial hero image for this Studio Global article: What is the CryptoBandits malware campaign disclosed by Microsoft in June 2026, including its clipboard-hijacking mechanism targeting Bitcoi. Article summary: On June 17, 2026, Microsoft disclosed a Windows-based cryptocurrency clipper campaign active since February 2026, tracked with CryptoBandits-related detections [2][1]. The malware combines clipboard hijacking, seed phras. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
openai.com
2026 年 6 月 17 日,微軟揭露了一個自 2026 年 2 月起活躍的 Windows 加密貨幣剪貼簿劫持程式(clipper)活動,代號為 CryptoBandits 。該惡意軟體結合了剪貼簿劫持、種子詞與私鑰竊取、內建 Tor 代理,以及類似蠕蟲的 USB 傳播能力,可在連網與氣隙環境中竊取加密貨幣 。
透過 Tor 隱匿指令與控制(C2):惡意軟體會啟動一個重新命名的 Tor 二進位檔案(ugate.exe),並在隱藏視窗中執行。它等待約 60 秒讓 Tor 啟動,產生一個受害者的唯一識別碼(GUID),並將受感染的裝置註冊到一個隱藏服務的指令與控制伺服器 。C2 通訊會透過本機 Tor SOCKS5 代理()進行,從而避開傳統的 IP 基礎架構 。
蠕蟲式 USB 傳播:初始感染是透過惡意的 .lnk 捷徑檔案,這些檔案可能透過 USB 隨身碟散播 。.lnk 會啟動一個蠕蟲組件,檢查裝置是否已受感染;若未受感染,則會透過 Tor 從 C2 伺服器下載惡意載荷 。當受感染的 USB 隨身碟在不同電腦之間移動時,這個機制可讓惡意軟體跨越氣隙環境傳播 。
其他能力:惡意軟體還能透過 Tor 上傳螢幕截圖;若 C2 伺服器回傳 EVAL 指令,它可以在執行階段執行攻擊者提供的任意程式碼 。