Microsoft Identifies New Crypto Malware Targeting Wallet Addresses and Private Keys

TheNewsCryptoPublicado a 2026-06-19Actualizado a 2026-06-19

Resumen

In February 2026, Microsoft identified a new crypto clipper malware, dubbed Trojan/CryptoBandits.A, targeting Windows systems. The malware spreads via malicious shortcut files on USB drives and operates without a traditional installer or control servers by leveraging Windows Script Host and ActiveX to deploy a Tor proxy. Once active, it runs two modules: one for spreading and another for stealing information. The malware continuously monitors the clipboard for 12 or 24-word recovery phrases, Bitcoin/Ethereum private keys, and wallet addresses. When a user copies a wallet address, the malware silently swaps it with one controlled by attackers to divert funds. It also captures screenshots to gather information on wallet balances and user activity, sending data through Tor connections. Additional capabilities include remote code execution and persistence via scheduled tasks. Microsoft advises disabling auto-run features, restricting script interpreters and executable shortcuts from USB drives, and monitoring for suspicious activities like JavaScript execution, localhost:9050 proxy use, PowerShell screenshot capture, and clipboard monitoring.

In February 2026, Microsoft Threat Intelligence and Microsoft Defender Experts found a crypto clipper attack. This was a campaign that was constructed on Windows. The malware exploits cryptocurrency holders through clipboard hijacking and searches for sensitive wallet information. These were reported by Microsoft through their blog.

Attackers primarily spread this malware through malicious .lnk shortcut files distributed on USB drives.The activation of this malicious code leads to the release of two modules by the malware. One module spreads the malware across systems, while the other operates as a clipper and information stealer. Microsoft Defender Antivirus identifies the threat as Trojan/CryptoBandits.A.

Unlike most malware operations, this one does not require the use of an installer or any control servers since it uses the Windows Script Host and ActiveX technology to launch a packaged Tor proxy. It then uses a SOCKS5 proxy on the infected computer and then connects to the control servers, which run on Tor Hidden Service.

Malware Snatches Wallet Information and Swaps Addresses

Following the infection of the system, the malware constantly tracks any clipboard content and looks for recovery phrases, private keys, and wallet addresses. According to Microsoft, the malware targets precisely 12-word and 24-word recovery phrases, Bitcoin private keys, and Ethereum private keys. It swaps the copied wallet addresses with ones controlled by the attackers before users finish their transactions.

The malware takes screenshots and sends them via Tor connections, which allows the attackers to get more information on wallet balances and activities of users. Also, Microsoft stated that the malware has the ability of remote code execution, giving the attackers the possibility to send additional instructions while ensuring persistence through the use of scheduled tasks and encryption of malicious parts of the malware.

Researchers identified several indicators of compromise, including suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommended that organizations disable auto-run features. They would also limit script interpreters and executable shortcuts from USB drives, and monitor any suspicious activity related to this. This malware campaign underscores the continued growth of cryptocurrency usage among investors and users.

Highlighted Crypto News:

Ethereum Foundation Faces Another Departure as Hsiao-Wei Wang Steps Down

TagsBlockchainCryptoCryptocurrencyMalwareMicrosoftWallet

Preguntas relacionadas

QWhat type of cyber attack did Microsoft identify in February 2026, and what does this malware specifically target?

AMicrosoft identified a crypto clipper attack. The malware targets cryptocurrency holders by hijacking their clipboards to steal sensitive wallet information, including recovery phrases, private keys, and wallet addresses.

QHow does the described malware initially spread to systems, and what is its primary method of operation?

AThe malware initially spreads through malicious .lnk shortcut files distributed on USB drives. Its primary method of operation is clipboard hijacking, where it monitors and swaps copied cryptocurrency wallet addresses with ones controlled by the attackers.

QWhat is unique about the command-and-control (C2) infrastructure of this malware campaign according to the article?

AUnlike most malware, it does not require an installer or traditional control servers. Instead, it uses Windows Script Host and ActiveX to launch a packaged Tor proxy, establishes a SOCKS5 proxy on the infected computer, and connects to control servers running as Tor Hidden Services.

QBesides clipboard monitoring, what other malicious capabilities does this malware possess?

ABeyond clipboard monitoring, the malware can take screenshots and send them via Tor connections, execute remote code, and ensure persistence on the infected system through scheduled tasks and encryption of its malicious components.

QWhat specific indicators of compromise (IoCs) and defensive measures does Microsoft recommend in response to this threat?

AIndicators of compromise include suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommends disabling auto-run features, limiting script interpreters and executable shortcuts from USB drives, and monitoring for related suspicious activity.

Lecturas Relacionadas

Analog Chips Are Picking Up

The analog chip market is showing signs of recovery, as evidenced by strong Q2 2026 earnings and guidance from major players like TI, STMicroelectronics, NXP, and onsemi. Revenue growth, improved order backlogs, and declining inventory levels across the supply chain indicate the start of a new upward cycle. Industrial markets led the recovery, followed by data centers and a notable pickup in automotive demand in Q2. The rebound is broad-based but uneven, with specific product areas like automotive analog, power management, and AI server power chains seeing tighter supply and pricing power, while consumer-focused and general-purpose segments remain competitive. A critical turning point is the normalization of inventory. After a prolonged multi-level destocking phase from OEMs to end customers, channel inventories have returned to healthy levels (e.g., NXP at 11 weeks). This has triggered restocking, particularly in automotive, and is now being supplemented by genuine end-demand from new system designs. AI is emerging as a key growth driver, creating new demand in two areas: 1) high-power data center infrastructure (power conversion, thermal management, signal integrity for GPUs, and optical modules) and 2) "Physical AI" in automotive, robotics, and industrial equipment (sensors, motor drivers, power management). This provides a growth vector less dependent on traditional consumer cycles. While some price increase notices have been issued, the revenue impact in Q3 is expected to be minimal, with volume driving growth. The recovery's sustainability will depend on the strength of underlying end-demand now taking over from inventory replenishment.

marsbitHace 4 min(s)

Analog Chips Are Picking Up

marsbitHace 4 min(s)

From 'Speculative Asset' to 'Next-Generation Financial Backbone': Is Crypto Evolving into a New TradFi World?

From "Speculative Asset" to "Next-Generation Financial Infrastructure": Is Crypto Evolving a New TradFi World? The crypto industry has long been dominated by the question: "What's the next asset to rise?" However, since 2026, a confluence of developments across different sectors suggests a fundamental shift. Crypto's capabilities in issuance, custody, trading, payment, and settlement are evolving beyond serving crypto assets themselves and are beginning to serve broader financial activities and the machine economy. A new layer of infrastructure is emerging beneath the speculative market. This transformation is driven by several key components reaching maturity and beginning to interconnect: 1. **Stablecoins as Programmable Money Interfaces:** Evolving from a tool for crypto trading, stablecoins are becoming a programmable form of money that applications can directly integrate and call like an API, facilitating global, 24/7 payments and settlements. 2. **RWA (Real-World Assets) as Programmable Objects:** Tokenization is moving beyond simple asset mapping. Initiatives like DTCC and Nasdaq are working to connect tokenized securities with real-world ownership, custody, and legal rights, allowing blockchain to host parts of traditional asset lifecycles. 3. **Prediction Markets for Price Discovery:** These markets aggregate dispersed information into real-time probability prices for future events, providing a price discovery layer that traditional finance often lacks. 4. **AI Agents as Economic Actors:** AI agents capable of autonomous decision-making are becoming new economic participants. Their need for frequent, low-value, automated payments is a natural fit for stablecoins and low-cost blockchains. Together, these elements form the early layers of a potential next-generation financial infrastructure: asset issuance/mapping, 24/7 payment/settlement, continuous trading/price discovery, and identity/permission management. The regulatory conversation is also shifting from whether crypto should exist to defining rules for its operation. However, the journey from a functional system to a reliable, widely-trusted infrastructure is long. Critical challenges remain, including establishing legal finality for on-chain actions, defining liability boundaries for AI agents, overcoming liquidity fragmentation, ensuring privacy for institutional use, and building the complex credit and risk management frameworks inherent to traditional finance. In summary, while speculation remains, crypto is undeniably building foundational capabilities beneath it. The most significant trend of 2026 is not a single breakout sector, but the convergence of previously independent pieces—programmable assets and money, continuous markets, autonomous software agents, and clearer regulation—into a more coherent system for real-world financial activity.

marsbitHace 10 min(s)

From 'Speculative Asset' to 'Next-Generation Financial Backbone': Is Crypto Evolving into a New TradFi World?

marsbitHace 10 min(s)

NEAR Co-Founder Proposes Creation of Protocol Sovereign Fund

NEAR co-founder Ilya Polosukhin has proposed creating a sovereign protocol fund to support ecosystem development through targeted funding. The fund aims to improve the project's sustainability, moving away from the current model where most L1 blockchains, including NEAR, pay for network security via token inflation, diluting non-staking holders. Inspired by sovereign wealth funds in countries like Singapore and Norway, the NEAR fund would use protocol revenue and treasury assets to generate yield, covering security costs and other public goods, ultimately aiming to lower inflation and potentially transition to a fixed token supply model. The initial phase would involve allocating around 30 million NEAR (approximately $50 million) to the fund. It would use protocol revenue to buy back NEAR and invest in yield-generating protocols. Profits would fund ecosystem initiatives like validator support and MPC provider payments. Unlike traditional sovereign funds holding fiat assets, this fund would primarily hold NEAR tokens, introducing additional risk that Polosukhin believes can be mitigated through diversified yield strategies. Token holders could participate in the fund's returns via the existing House of Stake delegation mechanism. The launch is planned to be gradual, with checkpoints to verify the model's effectiveness before allocating more capital. Polosukhin has opened the proposal for a two-week community discussion, emphasizing that final parameters will be determined by stakeholders, including validators and token holders.

cryptonews.ruHace 13 min(s)

NEAR Co-Founder Proposes Creation of Protocol Sovereign Fund

cryptonews.ruHace 13 min(s)

Trading

Spot
活动图片