Newsroom

Microsoft Warns of Sophisticated USB Crypto Clipper Malware Targeting Wallets

19 June, 2026   /   News   /  AI   /   Tags:  malware, usb, cryptobandits, microsoft, drives

Microsoft Warns of Sophisticated USB Crypto Clipper Malware Targeting Wallets

Microsoft Threat Intelligence has identified CryptoBandits, a self-propagating malware that spreads via USB drives, steals cryptocurrency credentials, and uses Tor for anonymous communication, posing risks to Windows users handling digital assets

Overview of the Emerging Threat

Microsoft has issued a warning about a new strain of malware specifically designed to target cryptocurrency investors and users. Dubbed CryptoBandits by security researchers, this threat combines traditional worm-like propagation with advanced data theft capabilities. Active since February 2026, it primarily affects Windows systems and focuses on stealing wallet addresses, seed phrases, and private keys.

The malware represents an evolution in threats against crypto holders, blending clipboard monitoring, screenshot capture, and remote access features. By disguising itself within everyday file interactions on removable media, it increases the chances of successful infection for users who frequently transfer files or connect external drives.

Key Characteristics of CryptoBandits
  • Spreads through booby-trapped .lnk shortcut files on USB drives
  • Monitors clipboard for BIP39 seed phrases, private keys, and wallet addresses
  • Replaces copied crypto addresses with attacker-controlled ones
  • Communicates via Tor network using a hidden SOCKS5 proxy
  • Captures screenshots periodically to monitor victim activity

How the Malware Infects and Operates

Infection typically begins when users insert an infected USB drive. The malware hides legitimate files on the drive and replaces them with malicious shortcuts that have similar names. Clicking these shortcuts triggers the payload, which then installs itself on the system.

Once active, CryptoBandits deploys obfuscated JavaScript components and sets up scheduled tasks for persistence. It installs a portable Tor client disguised as "ugate.exe" to establish anonymous connections to command-and-control servers. This setup allows attackers to issue commands, execute additional code, and exfiltrate data without relying on easily traceable infrastructure.

The clipper functionality runs continuously, checking the clipboard every few hundred milliseconds. It specifically looks for patterns matching 12- or 24-word BIP39 seeds, Ethereum keys, Bitcoin WIF private keys, and common wallet address formats for Bitcoin, Tron, and Monero. Stolen data, along with screenshots taken at regular intervals, is sent over the Tor network.

Microsoft's Detection Details
  • Defender Antivirus detects it as Trojan:Win32/CryptoBandits.A
  • Endpoint detection flags suspicious JavaScript processes and curl exfiltration
  • Indicators include localhost proxy usage on port 9050 and PowerShell screen capture

Advanced Features and Persistence Mechanisms

Beyond basic theft, the malware turns compromised systems into lightweight backdoors. Attackers can deploy remote code execution, maintain long-term access, and adapt their operations based on victim behavior. It also attempts to evade detection by excluding itself from antivirus scans and using script-based execution that avoids traditional installers.

Researchers noted the malware's ability to propagate further by infecting additional removable media connected to the compromised machine. This worm-like behavior increases its reach within organizations or among users sharing drives.

“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure. Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution.”
Microsoft Threat Intelligence

Rising Risks in the Crypto Security Landscape

This discovery comes amid a broader increase in Windows-targeted threats against cryptocurrency users. Similar malware families have been observed stealing browser extension data and wallet credentials, indicating attackers are focusing more resources on the growing crypto economy.

Users who frequently handle transactions, manage multiple wallets, or use USB drives for backups or file transfers face heightened risks. The combination of social engineering via disguised files and technical sophistication makes prevention more challenging than with conventional viruses.

Recommendations for Protection

Microsoft advises several practical steps to reduce exposure:

Protective Measures
  1. Disable AutoPlay for removable media
  2. Avoid executing shortcut files from USB drives
  3. Keep Microsoft Defender and Windows updated
  4. Use hardware wallets where possible and verify addresses manually
  5. Monitor for unusual scheduled tasks or Tor-related processes

Additional best practices include running regular security scans, being cautious with external storage devices, and double-checking transaction details before confirming transfers. For organizations, implementing strict USB policies and endpoint detection tools is essential.

While no single measure guarantees complete safety, combining vigilance with updated security software significantly lowers the likelihood of infection.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.