All incidents

Microsoft warns of USB‑spreading CryptoBandits cryptocurrency clipper

malwareclosedJun 18, 2026 — Jun 25, 2026
Windows USB‑spread cryptocurrency clipper malware hijacks clipboard via Tor

MICROSOFT has warned of a new cryptocurrency stealing worm that spreads through infected USB drives and hijacks clipboard contents to replace wallet addresses according to its latest threat intelligence.

The malware has been observed since February 2026 and targets anyone who copies cryptocurrency addresses for transactions.

The threat, tracked as Win32/CryptoBandits.A, propagates when a user opens a malicious shortcut file (.lnk) left on a removable drive, after which it copies itself to other USB devices that are subsequently connected as reported by SecurityOnline.

Once active, the malware continuously watches the clipboard for cryptocurrency wallet addresses or 12- and 24-word recovery seeds, swapping them for attacker‑controlled strings and capturing screenshots of the victim’s desktop.

It runs a lightweight Tor client bundled as a portable executable, routing its traffic through a SOCKS5 proxy to hide its communications with remote servers.

Stolen clipboard data, seed phrases and screen grabs are packaged and sent over the Tor network to servers operated by the threat actors, allowing the malware to exfiltrate information without opening obvious network ports per Ars Technica.

Microsoft notes that no CVE identifier has been assigned to this family, reflecting its reliance on script‑based techniques rather than a vulnerable software component.

The use of a portable Tor binary also helps the payload evade signature‑based antivirus scanners that look for known malicious binaries.

Telemetry shows the malware has been active since February 2026, with infections spiking whenever users share USB sticks in work‑from‑home or shared‑computer environments according to Microsoft.

No specific threat actor has been linked to the campaign, but the behaviour matches financially motivated groups that favour clipboard‑stealing and anonymous communication.

The emergence of this worm‑like clipper highlights how attackers are combining old propagation methods with modern privacy networks to stay under the radar.

Organisations should disable autorun for removable media and block the execution of .lnk files from USB drives through group policy or endpoint protection rules, which stops the initial infection vector.

Enabling behavioural detection in Microsoft Defender for Endpoint helps flag the unusual spawning of a Tor client from a user‑initiated shortcut or the repeated clipboard monitoring activity.

Limiting the use of PowerShell and restricting unsigned script execution reduces the malware’s ability to maintain persistence via scheduled tasks.

Finally, user training that emphasizes never opening unverified shortcuts on flash drives and always verifying cryptocurrency addresses before pasting them can blunt the social engineering edge.

Keeping Windows Defender definitions up to date ensures detection of the known indicators associated with Win32/CryptoBandits.A, while regular audits of scheduled tasks can uncover the malware’s persistence mechanisms.

Deploying application control solutions that only allow trusted binaries to run from removable media adds another layer of defence against similar USB borne threats.

Maintaining offline backups of cryptocurrency wallet seeds and regularly checking transaction histories limits the impact should a clipboard swap succeed.

Intelligence briefing updated Jun 25, 2026

Root sourcewww.microsoft.com
Timeline Coverage

Swipe to explore timeline