Microsoft discovers Windows-based encrypted clipboard Trojan horse

robot
Abstract generation in progress
CoinWorld News, Wu says has learned that Microsoft's Threat Intelligence Team and Microsoft Defender Expert Team have discovered a Windows-based encrypted clipboard Trojan horse that has been affecting users since February 2026. The malware spreads via malicious .lnk shortcuts, relies on Windows Script Host and ActiveX to launch a built-in Tor proxy, and polls hidden service C2 servers, capable of high-frequency theft of clipboard data, screen capture, replacement of cryptocurrency wallet addresses, and exfiltration of mnemonic phrases, private keys, and other information through Tor. Microsoft states that this Trojan also has worm-like propagation capabilities, hiding original files within USB storage devices and creating malicious shortcuts with the same name, while using scheduled tasks to achieve execution and persistence. Microsoft Defender Antivirus detects it as Trojan:Win32/CryptoBandits.A.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • 2
  • Share
Comment
Add a comment
Add a comment
AirdropOnTheDune
· 5h ago
This worm can also hide in USB drives to create doppelgängers, too shady.
View OriginalReply0
ChillBlock
· 6h ago
Windows users are trembling, the clipboard has become a high-risk zone
View OriginalReply0
ReefUnderTheMoonlight
· 6h ago
As long as Defender can block it, that's fine, but I no longer dare to copy the address.
View OriginalReply0
BorrowedSun
· 6h ago
Is it already being rumored since February 2026? Microsoft is only now disclosing it.
View OriginalReply0
TheWindOnTheBridgeIsTooStrong.
· 6h ago
CryptoBandits—this name is pretty straightforward: they’re all about snatching from the crypto world.
View OriginalReply0
OwlMarketMonitoringLamp
· 6h ago
Tor + Clipboard Monitoring + Screenshot Capture, a hacker combo that covers all bases.
View OriginalReply0
  • Pinned