{"id":13730,"date":"2026-06-19T10:03:37","date_gmt":"2026-06-19T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/19\/hackers-use-weaponized-windows-shortcuts-to-spread-crypto-clipper-across-usb-drives\/"},"modified":"2026-06-19T10:03:37","modified_gmt":"2026-06-19T10:03:37","slug":"hackers-use-weaponized-windows-shortcuts-to-spread-crypto-clipper-across-usb-drives","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/19\/hackers-use-weaponized-windows-shortcuts-to-spread-crypto-clipper-across-usb-drives\/","title":{"rendered":"Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives"},"content":{"rendered":"<p>    Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. <\/p>\n<p class=\"wp-block-paragraph\">The malware is not just a simple thief. It comes with worm-like behavior, Tor-based communication, and the ability to execute remote commands, making it one of the more sophisticated financially motivated threats seen this year.<\/p>\n<p class=\"wp-block-paragraph\">The attack begins the moment someone plugs in an infected USB drive and clicks on what looks like a familiar document. <a href=\"https:\/\/cybersecuritynews.com\/malicious-vs-code-extensions-attacking-windows-solidity-developers\/\" id=\"107726\" target=\"_blank\" rel=\"noreferrer noopener\">Unknown to the user, the file is actually a malicious shortcut (.lnk)<\/a> that silently launches harmful payloads in the background. <\/p>\n<p class=\"wp-block-paragraph\">The malware hides the original files, replaces them with look-alike shortcuts, and waits for unsuspecting users on other machines to fall into the same trap.<\/p>\n<p class=\"wp-block-paragraph\">Analysts from Microsoft Threat Intelligence and Microsoft Defender Experts identified this campaign and noted it has been actively targeting users for several months. <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/17\/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control\/\" id=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/17\/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft said in a report<\/a> shared with\u00a0Cyber Security News (CSN)\u00a0that the malware carries out high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution, all while routing its traffic through the Tor network.<\/p>\n<p class=\"wp-block-paragraph\">The threat leaves very little trace in the traditional sense. There is no standard installer, no exposed IP address to block, and the core payloads are encrypted and only unpacked at the moment of execution. This preparation suggests the people behind this campaign put significant effort into staying hidden.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgl5dayA0qYq_ELNO7vkshaZ58vzQVWb4AUpGhxsxy1T9zQ4bJ5s6T-vb-CP6ocBOFgaTVFgFRRLHdXix6Yb2D0z0SNyol7UwEiYIqqLBUvizPnUor-BvT-2oBSLLFKJfStBy4v4L8KfnI6lhEdmX0TGD3GQajV5xFB0_Le6j5_R5hztj6MpvEcy9MNCbk\/s16000\/High%2520level%2520execution%2520flow%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"High level execution flow (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">High level execution flow (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The financial damage can be immediate and severe. By quietly swapping copied wallet addresses with attacker-controlled ones, it can redirect entire cryptocurrency transactions without the victim noticing until the funds are already gone.<\/p>\n<h2 id=\"h-hackers-use-weaponized-windows-shortcuts\" class=\"wp-block-heading\"><strong>Hackers Use Weaponized Windows Shortcuts<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The malware\u2019s delivery method is deceptively simple. When a USB drive is inserted into an infected machine, the worm scans it for common file types like .doc, .xlsx, and .pdf. It hides the originals and creates shortcut versions with the same names, trapping the next person who picks up the drive.<\/p>\n<p class=\"wp-block-paragraph\">Once a victim clicks one of those shortcuts, the worm drops two malicious JavaScript files into a subfolder under \u201cC:UsersPublicDocuments\u201d using a five-character naming pattern for both the folder and file names. <\/p>\n<p class=\"wp-block-paragraph\">It also creates two scheduled tasks to keep the stealer running and the worm spreading to any new USB device connected to the machine.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/cybersecuritynews.com\/hannibal-stealer-with-stealth-obfuscation\/\" id=\"107080\" target=\"_blank\" rel=\"noreferrer noopener\">installation is wrapped in multiple layers of obfuscation<\/a>. The initial payload is a Python script protected with PyArmor and packaged into a standalone executable, while the JavaScript files each carry dual-layer obfuscation. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiPZcYKXTDhWCtH4EH3c9fWr01c49LmPGKCAZURV1QaTggUfB1pcYNrpaJREdDlNLHun8XJBspqrW_WzX4rP9VMhbTo_hz1KL-ofduOR-uNdAT8QosAYmvEQIbEo53I4YGSiKh9zkVySoLgvQ0ybIcvJp05XT1FU2RLQzJusBJSrg2mBehp-1ZaWuPo73A\/s16000\/CheckC2Command%2520function%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"CheckC2Command function (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">CheckC2Command function (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The malware also terminates itself if Task Manager is detected, making manual inspection significantly harder.<\/p>\n<h2 id=\"h-tor-routed-command-and-control-and-clipboard-theft\" class=\"wp-block-heading\"><strong>Tor-Routed Command and Control and Clipboard Theft<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">At the heart of this malware is a portable Tor client renamed \u201cugate.exe\u201d that launches in a hidden window. <\/p>\n<p class=\"wp-block-paragraph\">Once Tor is running, <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" id=\"6039\" target=\"_blank\" rel=\"noreferrer noopener\">the malware communicates with its command server<\/a> entirely through .onion addresses, making it nearly impossible to block based on destination domain alone.<\/p>\n<p class=\"wp-block-paragraph\">The clipper monitors the clipboard roughly every 500 milliseconds, looking for seed phrases, private keys, and wallet addresses. <\/p>\n<p class=\"wp-block-paragraph\">When it spots a copied wallet address, it silently replaces it with one controlled by the attacker. Supported formats include Bitcoin legacy, P2SH, Taproot, Bech32, Tron, and Monero addresses.<\/p>\n<p class=\"wp-block-paragraph\">The malware also captures five screenshots in ten-second intervals and sends them back to the attacker over Tor. This gives the operator a fuller picture of what the victim is doing with their funds. <\/p>\n<p class=\"wp-block-paragraph\">An EVAL command from the server can also push arbitrary code to run directly on the victim\u2019s machine.<\/p>\n<p class=\"wp-block-paragraph\">Defenders are strongly advised to disable AutoRun and AutoPlay for all removable media and to block .lnk execution from USB drives through Group Policy. <\/p>\n<p class=\"wp-block-paragraph\">Restricting script interpreters like wscript.exe and cscript.exe where not needed, and hunting for SOCKS5 proxy traffic on localhost:9050, are key steps to catching this threat early. <\/p>\n<p class=\"wp-block-paragraph\">Reviewing clipboard and screen-capture behaviors on devices handling financial workflows is equally important.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/1be2bb2c-826e-42c7-9d08-0faee920b2c7\/Hackers-Use-Weaponized-Windows-Shortcuts-to-Spread-Crypto-Clipper-Across-USB-Drives.pdf?AWSAccessKeyId=ASIA2F3EMEYEST6BDWVU&amp;Signature=R40XvOKBx5%2Bd%2Fa73F%2F8RWLZodic%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEO7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIA1NVoqWo7vbddrLsLQxeiDLGWhQ3ttMQ5MOiPyi6b%2FlAiAWi2%2FTCNcQTwz8JvGETeHPtjfijkfBKa3%2BUldSTOYHIyr8BAi3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM8LnTMOYz4ksfYAZmKtAE%2BW3dX7M%2FZGOdhlUGKco8ec8Jq48ch3cJe2cAglsgXUuUk9Y2ysp3%2Bn9g8G26oMbBnzHJTJ2iWDGkmj9TOo9kHx6b2HPS8LeucNiySyTPCuTUPxRaPqmTapAtvTAULsLLSkBsIECXIjHoes6VM0G4fbUpS3eZsHmUMKac2hopbhhofDgaXa5Ds10GGLJ9blsr5AUEr2tuKxH%2Fr5UguLYzLSysyFRs0%2F2flsPJ%2Fy5nNMGhWu5nxWPDiB9fktNTAWv72tRDJnwCrBCJHlY38Of80ji8y7H61QEVoYCvi8CCorU5i6I2XRoW1tHyUiIM4QkqU7BQVxDi8snX%2BNiBNrIk%2FXYIL2grx82JVAmAWc9BaGEOBN3GglAIZwzSFkfyIZmc8c8%2BaxS4GL3niuoxoRXIyxJhN2QgrmbU67Rdlyjr8MiGtcYVG5RuFCmHL5v83bHmGC2HkcB2tESMlEiTyvckfSIz3WfYjb1JJIAtoBBfKkW1BjgJBvAZ2sJWT%2BynAniSrwDCKynPWo8bMMPqU5aIAvqspRk8WdYrHLD8hlh3yRZBVFP3g4sFihWYKf19gimvNza2ZBxcDhA7b97ihiWHNrDJZevBiClTkiFFnR2%2FHkAxBO91ZsP1aBits1uLdjJpxzeQ%2Byza0XuIk68uL3XRv3OieZtCL2vRLsoYztUoGKllkGx9tMGA7WIXXJQqdr2cUsJtrf%2FIS3gHLENdmZAdvWCExuq1bN3QgCU5itXO6NUw5tSBksd95xt3yu3G3EE1oZvbTTeB6dCxI4W%2FRaXNpjDMpdPRBjqZAfvW4CsZ0bsPkGpRobmIBWcUiFKtihfUxzwZ4M4JA3vdsf7T9eo5p7gDX3Ea7nL5bCjXoK1%2BNpmQvNzQEZXMTfY5niHoX7JECHzNc2MWx%2B4k71YrjPEDj5duJOo1NLvURRG7hbhzqD8QtwR6B5Y6FxITRYVEJPVVQU6FubkjThRWSmhgmNlQcnt8inj1xjJ5ouj7rtE0gNwIYw%3D%3D&amp;Expires=1781850271\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SHA-256<\/td>\n<td>7630debd35cac6b7d58c4427695579b3e3a8b1cc462f523234cd6c698882a68c<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>a7abf1d9d6686af1cefcd60b17a312e7eb8cfe267def1ec34aeab6128c811630<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>23c1e673f315dafa14b73034a90dd3d393a984451ff6601b8be8142be6487b43<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>cf9fc891ea5ca5ecd8113ef3e69f6f52ff538b6cccbdaa9559106fc72bc6da30<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>100407796028bf3649752d9d2a67a0e4394d752eb8de86daa42920e814f3fae8<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>d14b80cbd1a19d4ad0473a0661297f8fdf598e81ff6c4ab24e212dcad2e54b3f<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>9d90f54ae36c6c5435d5b8bed40faf54cc91f6db28574a6310b5ffaeb0362e96<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>67fc5cf395e28294bbb91ed0e954fdf2e80ebd9119022a115a42c286dc8bacf5<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>0020d23b0f9c5e6851a7f737af73fd143175ee47054931166369edd93338538a<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>35a6bc44b176a050fd6824904b7604f0f45b0fdfa26bf9500b9e05973b387cfd<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>c824630154ac4fdfce94ded01f037c305eab51e9bef3f493c60ff3184a640502<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>d43bf94f0cb0ab97c88113b7e07d1a4024d1610617b5ad05882b1dbab89e15ba<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>b2777b73a4c33ac6a409d475057843be6b5d32262ef28a1f1ff5bb52e3834c5f<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>7787a9a7d8ae393aa32f257d083903c4dc9b97a1e5b0458c4cd480d4f3cb5b05<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>f3b54984caca95fd496bcfe5d7db1611b08d2f5b7d250b43b430e5d76393f9e0<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>20db98af3037b197c8a846dbf17b87fc6f049c3e0d9a188f9b9a74d3916dd5e1<\/td>\n<td>Crypto Clipper Worm<\/td>\n<\/tr>\n<tr>\n<td>Filename<\/td>\n<td>ugate.exe<\/td>\n<td>Portable Tor binary<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>cgky6bn6ux5wvlybtmm3z255igt52ljml2ngnc5qp3cnw5jlglamisad.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>gfoqsewps57xcyxoedle2gd53o6jne6y5nq5eh25muksqwzutzq7b3ad.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>he5vnov645txpcv57el2theky2elesn24ebvgwfoewlpftksxp4fnxad.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>lyhizqy2js2eh6ufngkbzntouiikdek5zsdj3qwa22b4z6knpqorgiad.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>j3bv7g27oramhbxxuv6gl3dcyfmf44qnvju3offdyrap7hurfprq74qd.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>shinypogk4jjniry5qi7247tznop6mxdrdte2k6pdu5cyo43vdzmrwid.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>7goms4byw26kkbaanz5a5u5234gusot7rp5imzc3ozh66wwcvmcudjid.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>facebookwkhpilnemxj7asaniu7vnjjbiltxjqhye3mhbshg7kx5tfyd.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>wt26llpl5k6gok3vnaxmucwgzv2wk3l7nuibbh25clghrtus3p5ctsid.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion<\/td>\n<td>C2 domain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-use-weaponized-windows-shortcuts\/\">Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-use-weaponized-windows-shortcuts\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. The malware is not just a simple thief. It [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13730","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13730"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13730"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13730\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}