Microsoft announces new encrypted clipboard Trojan threat: capable of stealthy propagation and hijacking digital asset wallet addresses

robot
Abstract generation in progress

Deep Tide TechFlow News. On June 19, the Microsoft Threat Intelligence Team disclosed a Windows encrypted clipboard trojan that has been active since February 2026. The malware combines “worm-like propagation + clipboard hijacking + Tor anonymous communications” to carry out attacks against digital asset users.

Microsoft’s analysis indicates that the malware spreads between removable storage devices through disguised shortcut (.lnk) files, and uses WScript and ActiveX to execute script logic, automatically deploying a local Tor client to enable anonymous control and data backhaul. The attack chain includes multiple malicious capabilities: continuously monitoring clipboard content, stealing mnemonics and private keys, capturing screenshots and uploading them, and performing “address replacement” when users copy cryptocurrency addresses—replacing the target address with a wallet address controlled by the attackers, thereby hijacking funds.

In addition, the trojan also has worm-like propagation capabilities: it can automatically copy itself to devices such as USB drives, create scheduled tasks for persistence, and include basic anti-analysis abilities (detecting Task Manager to evade debugging).

At the detection level, Microsoft has identified it as the Trojan:Win32/CryptoBandits series and intercepts it using behavioral indicators (such as abnormal WScript calls, localhost:9050 proxy traffic, and PowerShell screenshot behavior). Security researchers recommend focusing on protecting script execution paths and monitoring for abnormal local proxy traffic.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned