www.securityweek.com 6/19/2026, 11:46:34 AM · external

Microsoft flags CryptoBandits malware that steals crypto via .lnk

Microsoft flags CryptoBandits malware that steals crypto via .lnk
CyberSIXT Evidence Panel
Primary Source microsoft.com

MICROSOFT has issued a warning about a new malware called CryptoBandits, which targets Windows systems to steal cryptocurrency. The malware operates by using a lightweight backdoor, facilitating remote code execution, and data exfiltration. It has been active since February 2026, propagating via malicious shortcut files (.lnk) and deploying a Tor client for anonymous communication.

Once installed, it steals clipboard data, takes screenshots, and modifies cryptocurrency wallet addresses to redirect funds to attackers. The malware employs sophisticated techniques like task scheduling for persistence and extensive obfuscation to evade detection. Microsoft recommends organizations enhance their defenses against such script-based threats.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline