USB propagation: The physical weapon of the CryptoBandits malware to raid wallets.
Thinking that cryptocurrency hacks only happen online is a rookie mistake.
The poverty mindset underestimates physical threats and connects unverified USB drives to the computer that hosts their trading apps or browser extensions (MetaMask, Coinbase Wallet). Microsoft Threat Intelligence researchers have revealed that this new malware spreads like a computer worm by replacing legitimate files with malicious shortcuts carrying the .lnk extension. As soon as the victim clicks on the fake document, the worm installs in the background, starts taking screenshots of your balances, and scans your hard drive for files containing recovery phrases (Seed phrases).