Microsoft discloses new type of cryptocurrency theft malware Crypto Clipper, which has infected multiple Windows devices since February of this year

robot
Abstract generation in progress

BlockBeats News, on June 19,, Microsoft Security Blog published an article stating that Microsoft’s security research team has discovered a new type of cryptocurrency theft Trojan called Crypto Clipper. This malware has been active since February 2026, mainly spreading malicious .lnk shortcuts to infect Windows users via USB devices.

Crypto Clipper has an integrated Tor client that connects to .onion hidden services through a local SOCKS5 proxy, enabling covert C2 communication. Its main functions include high-frequency clipboard monitoring, stealing mnemonics and private keys, replacing cryptocurrency transfer addresses, capturing screenshots and uploading them, and receiving remote code execution commands.

Microsoft stated that this malware has worm-like propagation capabilities, automatically hiding original documents on USB drives and generating malicious shortcuts with the same name, while also creating scheduled tasks for persistence control. Researchers have detected it as Trojan:Win32/CryptoBandits.A and recommend users disable auto-run for removable devices, restrict script interpreter permissions, and closely monitor localhost:9050 Tor proxy traffic and abnormal clipboard access behaviors.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned