Newsroom
19 June, 2026 / News / AI / Tags: malware, usb, cryptobandits, microsoft, drives

Microsoft Threat Intelligence has identified CryptoBandits, a self-propagating malware that spreads via USB drives, steals cryptocurrency credentials, and uses Tor for anonymous communication, posing risks to Windows users handling digital assets
Microsoft has issued a warning about a new strain of malware specifically designed to target cryptocurrency investors and users. Dubbed CryptoBandits by security researchers, this threat combines traditional worm-like propagation with advanced data theft capabilities. Active since February 2026, it primarily affects Windows systems and focuses on stealing wallet addresses, seed phrases, and private keys.
The malware represents an evolution in threats against crypto holders, blending clipboard monitoring, screenshot capture, and remote access features. By disguising itself within everyday file interactions on removable media, it increases the chances of successful infection for users who frequently transfer files or connect external drives.
Infection typically begins when users insert an infected USB drive. The malware hides legitimate files on the drive and replaces them with malicious shortcuts that have similar names. Clicking these shortcuts triggers the payload, which then installs itself on the system.
Once active, CryptoBandits deploys obfuscated JavaScript components and sets up scheduled tasks for persistence. It installs a portable Tor client disguised as "ugate.exe" to establish anonymous connections to command-and-control servers. This setup allows attackers to issue commands, execute additional code, and exfiltrate data without relying on easily traceable infrastructure.
The clipper functionality runs continuously, checking the clipboard every few hundred milliseconds. It specifically looks for patterns matching 12- or 24-word BIP39 seeds, Ethereum keys, Bitcoin WIF private keys, and common wallet address formats for Bitcoin, Tron, and Monero. Stolen data, along with screenshots taken at regular intervals, is sent over the Tor network.
Beyond basic theft, the malware turns compromised systems into lightweight backdoors. Attackers can deploy remote code execution, maintain long-term access, and adapt their operations based on victim behavior. It also attempts to evade detection by excluding itself from antivirus scans and using script-based execution that avoids traditional installers.
Researchers noted the malware's ability to propagate further by infecting additional removable media connected to the compromised machine. This worm-like behavior increases its reach within organizations or among users sharing drives.
This discovery comes amid a broader increase in Windows-targeted threats against cryptocurrency users. Similar malware families have been observed stealing browser extension data and wallet credentials, indicating attackers are focusing more resources on the growing crypto economy.
Users who frequently handle transactions, manage multiple wallets, or use USB drives for backups or file transfers face heightened risks. The combination of social engineering via disguised files and technical sophistication makes prevention more challenging than with conventional viruses.
Microsoft advises several practical steps to reduce exposure:
Additional best practices include running regular security scans, being cautious with external storage devices, and double-checking transaction details before confirming transfers. For organizations, implementing strict USB policies and endpoint detection tools is essential.
While no single measure guarantees complete safety, combining vigilance with updated security software significantly lowers the likelihood of infection.









