{"id":601,"date":"2026-06-19T15:19:45","date_gmt":"2026-06-19T09:49:45","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=601"},"modified":"2026-08-18T15:22:03","modified_gmt":"2026-08-18T09:52:03","slug":"usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/","title":{"rendered":"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor"},"content":{"rendered":"<p>The USB LNK worm campaign highlights a familiar but still dangerous attack path: removable media. Instead of relying on phishing emails or malicious installers, the malware abuses Windows shortcut files placed on USB storage devices. When a user opens what appears to be a normal document, the shortcut executes malware in the background.<\/p>\n<p>This campaign is especially concerning because it does more than steal cryptocurrency wallet addresses. The Windows clipper malware monitors clipboard activity, replaces copied wallet values with attacker-controlled addresses, captures screenshots, communicates through Tor, and accepts commands from its command-and-control server.<\/p>\n<p>That combination turns clipboard hijacking into a broader backdoor risk. For enterprises, the lesson is clear: unmanaged USB access can expose endpoints to stealthy malware that blends financial theft, persistence, and remote control.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen removable media security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the USB LNK Worm Infection Works<\/h2>\n<p>The attack begins with malicious Windows shortcut files distributed through USB storage devices. These .lnk files appear to represent familiar document types, such as Word files, Excel spreadsheets, or PDFs. In reality, they contain arguments that trigger the worm payload.<\/p>\n<p>Once executed, the malware checks whether the device is already infected. If not, it retrieves and deploys additional payloads. It also scans the USB drive for common document files, hides the original files, and creates new shortcut files with the same names.<\/p>\n<p>This tactic increases the chance of reinfection and propagation. A user may think they are opening a legitimate document from the USB drive, but they are actually launching the worm again. If that same USB drive moves to another machine, the infection chain can continue.<\/p>\n<p>The worm also creates scheduled tasks to maintain persistence. This means the malware can continue running after restart and can keep watching for new USB drives to infect.<\/p>\n<h2>Clipboard Hijacking Is the Core Financial Threat<\/h2>\n<p>The clipper component focuses on cryptocurrency theft. Clipper malware monitors clipboard content because users frequently copy and paste wallet addresses, private keys, or seed phrases during crypto transactions.<\/p>\n<p>In this campaign, the malware checks clipboard data at high frequency. When it detects wallet-related patterns, it can extract seed phrases or private keys and send them to the attacker. It can also replace copied cryptocurrency wallet addresses with attacker-controlled alternatives.<\/p>\n<p>This is what makes clipboard hijacking so dangerous. The user may copy the correct destination address, but the malware silently swaps it before the paste action. If the user does not manually verify the full address, funds can be sent directly to the attacker.<\/p>\n<p>The malware reportedly targets multiple wallet formats, including Bitcoin, Ethereum, Tron, and Monero-related values. It also captures screenshots to give attackers more context about the victim\u2019s wallet, balance, or transaction workflow.<\/p>\n<h2>How Hexnode Helps Strengthen Removable Media Security<\/h2>\n<p>Hexnode UEM helps organizations manage Windows endpoints and reduce the risks associated with unmanaged removable media.<\/p>\n<p>With Hexnode UEM Media Management for Windows, administrators can control how managed Windows 10 Pro, Enterprise, and Education devices and Windows 11 Pro, Enterprise, and Education devices interact with removable disks. They can:<\/p>\n<ul>\n<li>Block removable disks completely<\/li>\n<li>Configure removable disks as read-only<\/li>\n<li>Control read access for removable disks<\/li>\n<li>Control write access for removable disks<\/li>\n<li>Control execute access for removable disks<\/li>\n<\/ul>\n<p>For threats like a USB LNK worm, execute restrictions are especially important. If users can view files but cannot run executables or scripts from removable storage, organizations reduce the attack surface created by untrusted USB devices.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM.png?format=webp\" class=\"resource-box__image\" alt=\"Why-Hexnode-UEM\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-Hexnode-UEM-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-Hexnode-UEM\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why Hexnode UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Discover how Hexnode UEM simplifies endpoint management, strengthens security, and drives business success.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/why-hexnode-uem\/'>\n                            Download the Brochure\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<p>Hexnode UEM also supports Microsoft Defender configuration for Windows devices. Through policy, administrators can:<\/p>\n<ul>\n<li>Configure Microsoft Defender settings<\/li>\n<li>Use Microsoft Defender Application Guard settings to control clipboard behavior within isolated browser sessions. However, Microsoft Defender Application Guard is deprecated for Microsoft Edge for Business and is no longer available starting with Windows 11, version 24H2.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> and <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-unified-endpoint-management-uem\/\">UEM<\/a> integration can further support incident response. Documented remediation workflows help security teams:<\/p>\n<ul>\n<li>Detect anomalies such as unauthorized process execution<\/li>\n<li>Identify known malware signatures<\/li>\n<li>Validate threat context<\/li>\n<li>Isolate affected devices from the network<\/li>\n<li>Terminate suspicious processes based on device severity<\/li>\n<\/ul>\n<p>This matters because USB-based malware often needs fast containment.<\/p>\n<p>If Hexnode XDR detects unauthorized process execution, known malware signatures, or high-severity threat signatures, security teams can isolate the affected device and terminate malicious processes.<\/p>\n<h2>Conclusion<\/h2>\n<p>The USB LNK worm campaign shows how a removable media infection can evolve into a serious endpoint compromise. What starts as a malicious shortcut on a USB drive can become persistent Windows clipper malware with clipboard hijacking, screenshot theft, Tor-based command-and-control, and runtime code execution.<\/p>\n<p>For organizations, the threat reinforces a simple point: removable media security cannot depend on trust or user caution alone. Enterprises need enforceable USB controls, strong endpoint policies, behavioral detection, and rapid containment workflows.<\/p>\n<p>By managing USB access, restricting execution from removable disks, configuring endpoint security policies, and responding quickly to suspicious activity, organizations can reduce the risk of USB-borne malware turning into a wider security incident.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop USB Malware Before Execution<\/h5><p>Control removable media, restrict execution, and contain Windows threats faster with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why do attackers use LNK files for malware delivery?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Attackers use LNK files because they can disguise malicious execution behind familiar file names and icons. A shortcut may look like a document while silently launching scripts, commands, or payloads in the background.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is clipboard hijacking limited to cryptocurrency theft?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Crypto theft is a common use case because wallet addresses are frequently copied and pasted. However, clipboard hijacking can also expose passwords, recovery codes, internal links, access tokens, and other sensitive copied data.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The USB LNK worm campaign highlights a familiar but still dangerous attack path: removable media&#8230;.<\/p>\n","protected":false},"author":6,"featured_media":602,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>USB LNK Worm Enables Windows Clipper Malware<\/title>\n<meta name=\"description\" content=\"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"USB LNK Worm Enables Windows Clipper Malware\" \/>\n<meta property=\"og:description\" content=\"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-19T09:49:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:52:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor\",\"datePublished\":\"2026-06-19T09:49:45+00:00\",\"dateModified\":\"2026-08-18T09:52:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/\"},\"wordCount\":954,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/\",\"name\":\"USB LNK Worm Enables Windows Clipper Malware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp\",\"datePublished\":\"2026-06-19T09:49:45+00:00\",\"dateModified\":\"2026-08-18T09:52:03+00:00\",\"description\":\"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"USB LNK Worm Enables Windows Clipper Malware","description":"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/","og_locale":"en_US","og_type":"article","og_title":"USB LNK Worm Enables Windows Clipper Malware","og_description":"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-19T09:49:45+00:00","article_modified_time":"2026-08-18T09:52:03+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor","datePublished":"2026-06-19T09:49:45+00:00","dateModified":"2026-08-18T09:52:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/"},"wordCount":954,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/","url":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/","name":"USB LNK Worm Enables Windows Clipper Malware","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp","datePublished":"2026-06-19T09:49:45+00:00","dateModified":"2026-08-18T09:52:03+00:00","description":"USB LNK worm spreads through removable media, enabling clipboard hijacking, Tor-based C2, and Windows clipper malware risks for enterprises.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/USB-LNK-Worm-Turns-Clipboard-Theft-Into-a-Tor-Backed-Windows-Backdoor.png?format=webp","width":1340,"height":700,"caption":"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/usb-lnk-worm-turns-clipboard-theft-into-a-tor-backed-windows-backdoor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"USB LNK Worm Turns Clipboard Theft Into a Tor-Backed Windows Backdoor"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=601"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/601\/revisions"}],"predecessor-version":[{"id":604,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/601\/revisions\/604"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/602"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}