Back to news

Clipboard Hijacker and Rising Ransomware Gang Signal Escalating Threats

Microsoft exposes a USB-spread crypto clipper using Tor-based infrastructure while researchers zero in on the operator behind fast-growing ransomware group The Gentlemen.

Clipboard Hijacker and Rising Ransomware Gang Signal Escalating Threats

What happened

Microsoft's Defender Security Research Team has released technical details on a cryptocurrency clipper campaign active since February 2026 that spreads via USB drives using Windows LNK shortcut files. The malware leverages Windows Script Host and ActiveX components to silently launch a bundled Tor proxy, routing communications through a hidden-service command-and-control server that makes attribution and takedown significantly more difficult. Separately, cybersecurity journalist Brian Krebs has published an investigation into The Gentlemen, a ransomware collective that has rapidly climbed to become the second most prolific ransomware group by confirmed victim count, drawing talent through a 90-percent affiliate payout model and aggressive underground recruitment.

Why it matters for your business

The USB-based clipper presents a concrete risk for any organization where physical media moves between workstations — including manufacturing floors, logistics hubs, and shared office environments — as it silently replaces cryptocurrency wallet addresses copied to the clipboard, redirecting payments without triggering standard alerts. The Tor-based C2 architecture means conventional IP-blocking controls offer limited protection, placing greater weight on endpoint detection and behavioral monitoring tools. The Gentlemen's affiliate revenue model mirrors legitimate sales commission structures, effectively lowering the barrier for skilled but previously unaffiliated criminals to join high-impact ransomware operations. Organizations should audit USB port policies, enforce application allowlisting, and verify that endpoint security tools include behavioral detection capable of flagging anomalous script-host and ActiveX activity.

What to watch next

Microsoft has not yet disclosed the full geographic scope of the clipper campaign, and follow-on reporting is expected to reveal whether specific industry sectors have been disproportionately targeted. On the ransomware front, Krebs's identification of a suspected administrator for The Gentlemen could accelerate law enforcement action, though historically such exposure has prompted groups to rebrand rather than dissolve. Both developments underscore a broader trend of threat actors building resilient, anonymized infrastructure that complicates disruption efforts even when operatives are publicly named.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp