Cybersecurity Events: USB Worm Targets Crypto Wallets, Apple Closes Hole in Beats Studio Buds
Cybersecurity events over the past week have once again been closely tied to cryptocurrencies: attackers promoted a clipper through fake reputations on GitHub and YouTube, a USB worm spread via hidden Windows shortcuts, and researchers discovered a new Android trojan for stealing digital assets. These episodes clearly illustrate the cybersecurity trends that will be particularly noticeable in 2026: attacks on trust in public platforms, data theft via mobile applications, the use of AI in social engineering, and protecting crypto wallets from address substitution.
Main Episodes of the Week:
- Crypto Clipper - disguised as trading and betting tools, with trust bolstered by inflated likes, comments, and downloads.
- USB Worm - infected Windows systems through .LNK files on flash drives and substituted crypto wallet addresses in the clipboard.
- Cryptocurrency Money Laundering Network - 23 people were arrested in South Korea in connection with the transfer of funds for a Cambodian phishing syndicate.
- Android Trojan Rokarolla - Zimperium experts described the malware with full device control capabilities.
Fake Reputation Helped Promote Crypto Clipper
An unknown attacker launched a large campaign to spread malware, using techniques similar to legitimate marketing. Check Point Research described this scheme as creating a fake "Reputation Economy": around the malicious files, a facade of popularity and trust was pre-formed.
The main goal of the campaign was to install crypto clippers on victims' devices disguised as trading programs in the Solana ecosystem and as tools for predicting bets. For the field of information security, this is a telling case: attackers are increasingly targeting not only vulnerabilities in code but also user trust in public platforms.
The clipper itself is written in Rust and designed for Windows and macOS. After installation, it discreetly monitors the clipboard. If a user copies a cryptocurrency wallet address, the malware instantly replaces it with the attacker's credentials, causing the transfer to go to the criminal instead of the intended recipient.
To lull the vigilance of crypto investors and online gamers, the campaign author built a network of fake accounts on various platforms. Analysts noticed coordinated activity on VirusTotal: dozens of profiles left positive comments and likes, creating the impression that the malicious files were safe.
- On GitHub and SourceForge, the attacker used a network of accounts for mutual promotion of repositories. On SourceForge, the number of downloads was artificially inflated to 44,000 using a farm of Android devices.
- On YouTube, a channel with an audience of over 91,000 subscribers was used to advertise the programs. Tutorial videos were voiced using AI voice generators, and inflated positive comments appeared under the videos.
- To give the tools a legitimate appearance, press release distribution services, including EIN Presswire, were used. Such publications then automatically appeared on partner news sites.
Check Point Research believes that manipulations on crowdsourcing platforms indicate a new dangerous phase of social engineering. If such a model becomes established, it could be applied not only for clippers but also for the mass distribution of ransomware and more advanced info stealers.
USB Worm Infected Computers via Hidden Windows Shortcuts
Microsoft has revealed details of a campaign involving self-replicating malware that targeted cryptocurrencies. The infection began when a user opened a modified .LNK shortcut on a USB drive.
Once launched, the worm downloaded additional components from a command server in the .onion zone. It then searched the computer for user documents, hid the originals, and replaced them with malicious shortcuts bearing the same names. As a result, the program activated every time the device owner attempted to open a familiar work file.
To spread, the malware created a scheduled task that monitored the connection of external drives. As soon as a new USB stick was inserted into the computer, the worm immediately copied itself onto it. This scenario resembles old attacks via removable drives, but this time it was adapted for cryptocurrency theft.
The stealer only began operating if the Task Manager was not open in the system. It established a connection with the command server through a built-in Tor executable and checked the clipboard every half second. Items of interest included:
- BIP39 seed phrases of 12 or 24 words.
- Bitcoin wallet addresses: Legacy, P2SH, Bech32, and Taproot.
- Ethereum, Tron, and Monero wallet addresses.
When a user copied a wallet address, the program replaced it with the attacker's address. To make the substitution less noticeable, the algorithm selected credentials with similar starting characters.
The malware did not limit itself to a single clipboard interception. Every ten seconds, it took five screenshots and sent them to operators via Curl. By command from the server, the program could download and execute arbitrary JavaScript scripts on the infected machine.
The activity of this USB worm has been recorded since at least February. Microsoft emphasizes that the most noticeable signs of infection are related not to signatures but to system behavior: suspicious background activity and unexpected launches of Curl, PowerShell, and network connections with localhost:9050 — the standard Tor proxy port.
South Korea Closes Cryptocurrency Money Laundering Network
South Korean law enforcement has arrested 23 suspects in a case involving money laundering for a Cambodian phishing group. According to investigators, the money was funneled through a complex chain of transactions involving local and foreign cryptocurrency exchanges.
From February 2024 to April 2025, participants in the scheme moved approximately 11.1 million USDT. The scale of the infrastructure turned out to be significant: around 11,300 accounts were used for operations. These transit accounts were linked to stolen funds totaling about $17 million, obtained from 265 incidents.
During the raids, police seized criminal proceeds amounting to 650 million won, or approximately $430,000. The operation is still ongoing: the alleged organizer remains at large. A Red Notice has been issued by Interpol against him, indicating international wanted status and possible extradition.
Rokarolla Gains Full Control Functions Over Android
Zimperium specialists have discovered the Android Trojan Rokarolla, aimed at stealing cryptocurrencies. It has been found to possess 137 remote commands. This set allows it to intercept PIN codes, read and send SMS, manage the clipboard, and disable built-in OS security mechanisms.
Malware spreads through websites that impersonate download pages for popular services like TikTok and Google Chrome. In the first stage, the victim installs an application that looks like a system component of Google Play Protect. Then, the dropper uses social engineering to convince the user to grant access to <
Once this permission is granted, the malware deploys its main payload and immediately disables the real Play Protect scanner. For mobile device security, such permissions remain one of the most risky elements: they give the application too much control over the user's actions.
Rokarolla downloads fake HTML authorization pages for each active application from the target list. When the smartphone owner opens a real crypto wallet, the Trojan overlays it with a fake window and steals the entered data.
A separate overlay mimics the standard Android lock screen. This way, the malware can steal the PIN code, password, or graphical key, and operators can manage the device even after it is locked. To steal cryptocurrency, the Trojan also uses a clipper: it monitors the clipboard and changes copied wallet addresses to those of the attackers.
To bypass two-factor authentication, Rokarolla reads all SMS on the device and can send messages on its own. If the Trojan becomes the default app for calls and SMS, it can block incoming calls. In such cases, a warning call from the bank's anti-fraud system simply does not reach the owner.
The main recommendation from experts is to be particularly cautious when granting access to <
>. This permission triggers the main attack chain and turns an ordinary application into a tool for complete control over the smartphone.
Crypto Scammers Start Sending Couriers for Cash
Operators of cryptocurrency schemes <
Typically, scammers start by communicating on social media, messengers, or dating sites. They gradually gain trust and then offer to invest in a fake investment platform. If a bank transfer fails, the victim is convinced to withdraw cash— for example, under the pretext of a temporary <
After this, a courier is sent to the person. For identification, a pre-agreed password or the serial number of a specific dollar bill is used. Once they receive the money, the scammers show the victim's virtual wallet a balance increase, and then demand new payments— for instance, supposedly to pay taxes before withdrawing funds.
According to the FBI for 2025, cryptocurrency and investment schemes remain the most destructive form of cybercrime in the U.S. They accounted for 49% of all incidents, with total losses reaching $8.6 billion.
Apple Closes Dangerous Vulnerability in Beats Studio Buds
Apple has released a firmware update for Beats Studio Buds and fixed a high-severity vulnerability. The issue was reported by SentinelOne experts back in January: the flaw allowed attackers to secretly connect to the headphones and use their microphone for surveillance.
The vulnerability has been assigned the identifier CVE-2025-20701. It is related to improper authorization in the Bluetooth audio SDK from chip developer Airoha. If the headphones had not yet been paired and were in search mode, an attacker within Bluetooth range could connect their equipment to them without the user's consent.
The issue was resolved in Beats firmware version 1B211. The exploit could be triggered via standard Bluetooth or Bluetooth Low Energy without any authentication. In addition to eavesdropping, the attack provided almost complete control over the device: the attacker could read and overwrite the RAM and flash memory of the headphones.
Moreover, attackers could intercept trusted connections with previously paired smartphones. This opened the door to more complex multi-stage attacks, where information technologies such as wireless protocols became part of the compromise chain.
Cybersecurity Events, Incidents, and Basic Principles
An information security event is a recorded action or change that may affect the protection of a system or data. Examples include connecting a USB drive, launching an unusual process, logging into an account from a new device, changing access rights, or establishing a network connection with a suspicious node.
A cybersecurity incident is an event or chain of events that already compromises security or poses a direct threat. Such incidents include USB worm infections, clipboard address substitution of cryptocurrency wallets, theft of seed phrases, phishing authorization through fake windows, and unauthorized Bluetooth connections to devices.
Three basic principles of cybersecurity:
- Confidentiality - Access to data is granted only to those who truly need it.
- Integrity - Data should not be altered, substituted, or damaged unnoticed.
- Availability - Systems and services must operate when needed by users and businesses.
Infrastructure protection is built around updates, access rights control, monitoring suspicious processes, checking network connections, and careful handling of external media. Data protection relies on backups, encryption, multi-factor authentication, least privilege, and careful verification of where money or confidential information is being sent.
Cybersecurity Rules for Users
10 rules to help reduce the risk of hacking and data theft:
- Use different complex passwords for important services.
- Enable multi-factor authentication where available.
- Check the website address before entering your login, password, or seed phrase.
- Do not install applications from dubious sources.
- Be cautious when granting access to Special Features and other sensitive permissions.
- Do not open files and shortcuts from unknown USB drives.
- Update your operating system, browser, applications, and device firmware.
- Verify the wallet address after pasting from the clipboard before making a crypto transfer.
- Store backups of important data separately from the main device.
- Do not trust a project's popularity based solely on likes, comments, downloads, or video reviews.
7 Rules for Safe Internet Use
- Do not click on suspicious links from emails, messengers, and comments.
- Do not enter payment details and passwords on pages that look unfamiliar.
- Check the domain of the website, especially when it comes to wallets, exchanges, and investments.
- Do not send money to people you met on social media or dating sites.
- Do not download investment and trading tools from unverified pages.
- Do not share codes from SMS, PIN codes, and seed phrases with third parties.
- Be cautious of urgent requests, promises of high returns, and pressure from the interlocutor.
Employee training is best conducted not through one-off lectures, but through short, regular practices. Effective methods include analyzing real attacks, phishing email drills, instructions for handling USB drives, checklists for cryptocurrency payments, response scenarios for suspicious applications, and clear rules for granting access rights.
Calendars of cybersecurity conferences and events should be sought on the websites of relevant associations, major cybersecurity vendors, in the events sections of technology media, on university pages, and in professional communities. Before registering, it is useful to check the organizer, date, program, participation format, and list of speakers.
Other Important News of the Week
Aztec --- an outdated contract on the network was hacked for $2 million.
Polymarket --- Kentucky has filed a lawsuit against the platform, following other states.
Social Media in the UK --- authorities plan to ban access for children under 16.
Cryptocurrency in Russia --- the Supreme Court recognized it as a subject of theft.
Bitbank --- the exchange threatened to block transactions related to Polymarket.
What to Read on the Weekend
Ideas that change the world often emerge from the periphery --- from people whom contemporaries consider oddballs. ForkLog explores why pioneers like Jack Parsons often remain in the shadows of the revolutions they helped create. Artificial intelligence is already influencing cybersecurity from both sides: it helps defenders notice anomalies faster, search for malicious activity, and analyze large data sets, while simplifying phishing, generating fake voices, and creating convincing bait for attackers. Such stories serve as a reminder that technological shifts rarely begin in the spotlight.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Andrew Kang's Shareholder Letter: Robotics Investment Reaches a Turning Point, Private Valuations Still Severely Lagging

SMEs: The Government Launched the RIMI Six Months After Its Approval in Congress

Debt: The Treasury will offer securities maturing before the elections to renew about $12.6 trillion

SQD adds validated onchain data to Google Cloud BigQuery

Term Finance closes Meta Vaults after estimated $8.5M attack

CryptoQuant's Risk for Bitcoin: Ki Young Ju Identifies the Main Threat to Bitcoin

Judicial Investigation Agency Raids Properties of Alias 'Gato's' Children in Costa Rica Case Expansion

Goldman Sachs backs crypto stocks amid Bitcoin breakout

Fixed-term deposits in dollars: what you earn by investing $2,000

Bitcoin Spot Demand: The Signal That Hadn't Reappeared Since the October 2025 Record

Cofund Maps Over 24 Bitcoin Covenant Use Cases

Purchase of Cryptocurrency Through Intermediaries Will Be Available to Unqualified Investors

Saudi Arabia Leads Mecca Agreement, Oil Dollar System Faces New Trust Test

$1 Billion in 48 Hours: X Prepares Crypto Trading Function on Feed

The forex complex: How retail traders are adapting to volatile 2026 markets

Trump Beats the Fed: How Trading Boom Explodes in the UAE

LayerZero Unveils ATLAS Exchange Engine

Chile Requests the Extradition of Two Venezuelans Who Laundered Nearly USD 19 Million for the Tren de Aragua

Crypto investors should favor systematic strategies over Fed predictions, Moon Pursuit Capital says

MEXC stock futures trading volume in Asia surges over 3,300% in Q2

Operation Lighthouse: 14,000 Leads Delivered to Investigators Against Child Exploitation Networks

Binance founders used ‘The Simpsons’ codenames, former employees share

Crypto: Solana ETFs Record Their Biggest Day of the Year

Ray Dalio Warns of U.S. Debt Crisis and Recommends Gold and Bitcoin as Protection

Xbox and PlayStation Reassess Their Multiplatform Strategy, Emphasizing Exclusivity Again

The new Resident Evil movie will bring action to the first person

What is the cost of cheap borrowing?

Interview: Aptos CEO on AI Agents, Stablecoins, and Machine Commerce

Chainalysis identifies 7,700 suspect accounts in CSAM crypto operation





