Microsoft Identifies New Crypto Malware Targeting Wallet Addresses and Private Keys

TheNewsCryptoPublicado a 2026-06-19Actualizado a 2026-06-19

Resumen

In February 2026, Microsoft identified a new crypto clipper malware, dubbed Trojan/CryptoBandits.A, targeting Windows systems. The malware spreads via malicious shortcut files on USB drives and operates without a traditional installer or control servers by leveraging Windows Script Host and ActiveX to deploy a Tor proxy. Once active, it runs two modules: one for spreading and another for stealing information. The malware continuously monitors the clipboard for 12 or 24-word recovery phrases, Bitcoin/Ethereum private keys, and wallet addresses. When a user copies a wallet address, the malware silently swaps it with one controlled by attackers to divert funds. It also captures screenshots to gather information on wallet balances and user activity, sending data through Tor connections. Additional capabilities include remote code execution and persistence via scheduled tasks. Microsoft advises disabling auto-run features, restricting script interpreters and executable shortcuts from USB drives, and monitoring for suspicious activities like JavaScript execution, localhost:9050 proxy use, PowerShell screenshot capture, and clipboard monitoring.

In February 2026, Microsoft Threat Intelligence and Microsoft Defender Experts found a crypto clipper attack. This was a campaign that was constructed on Windows. The malware exploits cryptocurrency holders through clipboard hijacking and searches for sensitive wallet information. These were reported by Microsoft through their blog.

Attackers primarily spread this malware through malicious .lnk shortcut files distributed on USB drives.The activation of this malicious code leads to the release of two modules by the malware. One module spreads the malware across systems, while the other operates as a clipper and information stealer. Microsoft Defender Antivirus identifies the threat as Trojan/CryptoBandits.A.

Unlike most malware operations, this one does not require the use of an installer or any control servers since it uses the Windows Script Host and ActiveX technology to launch a packaged Tor proxy. It then uses a SOCKS5 proxy on the infected computer and then connects to the control servers, which run on Tor Hidden Service.

Malware Snatches Wallet Information and Swaps Addresses

Following the infection of the system, the malware constantly tracks any clipboard content and looks for recovery phrases, private keys, and wallet addresses. According to Microsoft, the malware targets precisely 12-word and 24-word recovery phrases, Bitcoin private keys, and Ethereum private keys. It swaps the copied wallet addresses with ones controlled by the attackers before users finish their transactions.

The malware takes screenshots and sends them via Tor connections, which allows the attackers to get more information on wallet balances and activities of users. Also, Microsoft stated that the malware has the ability of remote code execution, giving the attackers the possibility to send additional instructions while ensuring persistence through the use of scheduled tasks and encryption of malicious parts of the malware.

Researchers identified several indicators of compromise, including suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommended that organizations disable auto-run features. They would also limit script interpreters and executable shortcuts from USB drives, and monitor any suspicious activity related to this. This malware campaign underscores the continued growth of cryptocurrency usage among investors and users.

Highlighted Crypto News:

Ethereum Foundation Faces Another Departure as Hsiao-Wei Wang Steps Down

TagsBlockchainCryptoCryptocurrencyMalwareMicrosoftWallet

Preguntas relacionadas

QWhat type of cyber attack did Microsoft identify in February 2026, and what does this malware specifically target?

AMicrosoft identified a crypto clipper attack. The malware targets cryptocurrency holders by hijacking their clipboards to steal sensitive wallet information, including recovery phrases, private keys, and wallet addresses.

QHow does the described malware initially spread to systems, and what is its primary method of operation?

AThe malware initially spreads through malicious .lnk shortcut files distributed on USB drives. Its primary method of operation is clipboard hijacking, where it monitors and swaps copied cryptocurrency wallet addresses with ones controlled by the attackers.

QWhat is unique about the command-and-control (C2) infrastructure of this malware campaign according to the article?

AUnlike most malware, it does not require an installer or traditional control servers. Instead, it uses Windows Script Host and ActiveX to launch a packaged Tor proxy, establishes a SOCKS5 proxy on the infected computer, and connects to control servers running as Tor Hidden Services.

QBesides clipboard monitoring, what other malicious capabilities does this malware possess?

ABeyond clipboard monitoring, the malware can take screenshots and send them via Tor connections, execute remote code, and ensure persistence on the infected system through scheduled tasks and encryption of its malicious components.

QWhat specific indicators of compromise (IoCs) and defensive measures does Microsoft recommend in response to this threat?

AIndicators of compromise include suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommends disabling auto-run features, limiting script interpreters and executable shortcuts from USB drives, and monitoring for related suspicious activity.

Lecturas Relacionadas

Q2 Wall Street Institutional Crypto Holdings: Most Institutions Increased Positions Against the Trend, ETH Exposure Outperformed BTC Across the Board

In Q2 2024, despite a roughly 14.2% decline in Bitcoin's price, many Wall Street institutions increased their crypto holdings, revealing a divergence from ETF flow trends. Overall institutional Bitcoin exposure grew by 7.5% to ~536k BTC, while aggregate spot Bitcoin ETF holdings declined. Notably, exposure concentration increased, with fewer reporting institutions holding larger positions. A key trend was the significant outperformance of Ethereum (ETH) exposure growth over Bitcoin (BTC) among major banks. For instance, JPMorgan's ETH exposure surged 67.3% versus 12.2% for BTC, and Morgan Stanley's ETH exposure grew 18.6% versus 3.7%. Individual bank holdings of Ethereum ETFs like ETHA saw dramatic increases, even as the overall Ethereum ETF market experienced net outflows during the quarter. Trading firms like Jane Street significantly rebuilt its iShares Bitcoin Trust (IBIT) position, while several hedge funds, including Brevan Howard and Graham Capital, reduced spot ETF holdings but added substantial option positions (both calls and puts), indicating more complex strategies. Institutions showed diverging views on crypto-related equities: some sold shares of MicroStrategy (MSTR) after its announced Bitcoin sales, while others like Renaissance Technologies and BlackRock were buyers. New entrants like Spain's Santander Bank disclosed initial crypto ETF positions. Meanwhile, long-term holders like Abu Dhabi's sovereign wealth funds paused their accumulation, and Harvard's endowment maintained a flat Bitcoin position. Key signals include the deepening institutionalization of crypto assets, a clear institutional preference for accumulating Ethereum, and growing divergence in views on crypto equities. This institutional buying in Q2 preceded a price recovery and renewed inflows into Ethereum ETFs in July and August.

marsbitHace 7 min(s)

Q2 Wall Street Institutional Crypto Holdings: Most Institutions Increased Positions Against the Trend, ETH Exposure Outperformed BTC Across the Board

marsbitHace 7 min(s)

TSMC, Another Winning Bet

TSMC Gains Another Strategic Advantage as Samsung Delays 1.4nm Process Samsung Foundry has adjusted its advanced process roadmap, postponing the mass production timeline for its 1.4nm process from 2027 to 2029. This two-year delay signals a strategic shift from aggressively pursuing the next node to focusing on maturing and scaling its 2nm platform. Samsung plans to extend the commercial lifespan of its 2nm technology through derivative versions optimized for different applications, including those incorporating backside power delivery for AI and HPC chips. A notable aspect of this shift is Samsung's cautious approach toward High-NA EUV lithography. The company views it as essential for 1nm-class nodes and beyond but not as an immediate necessity for 1.4nm, opting instead to refine its existing Low-NA EUV-based processes. This highlights a broader industry trend where the competition is evolving beyond simply reaching the next node. Success now depends on achieving high yield, managing soaring costs, integrating new transistor architectures like GAA, and delivering a compelling overall package of performance, power efficiency, and area (PPA) at a viable cost. While Samsung consolidates its 2nm efforts, TSMC continues its advance. Its N2 node is in production, and the A16 node (post-2nm, ~1.6nm) is scheduled for mass production in the second half of 2026. A16 introduces TSMC's Super Power Rail backside power delivery technology, which is expected to deliver significant performance and power efficiency gains. TSMC's previously stated cautious stance on High-NA EUV appears validated by Samsung's roadmap adjustment. The delay underscores that the competition in leading-edge semiconductor manufacturing is entering a new phase. It is no longer just a race to smaller node numbers but a multifaceted contest involving process maturity, yield, cost, design-technology co-optimization (DTCO), and advanced packaging. Samsung aims to solidify its 2nm platform over the next three years. However, as it targets 1.4nm for 2029, the industry will be watching how far ahead TSMC and Intel have moved by then.

marsbitHace 12 min(s)

TSMC, Another Winning Bet

marsbitHace 12 min(s)

The Top 'Doghead Strategist' in the Blind Date Scene: Doubao

"The 'First Dating Strategist': AI's New Role in Love and Deception This article explores the growing, and often troubling, reliance on AI, specifically tools like the chatbot 'Doubao', for navigating modern relationships. It begins by highlighting a cultural shift where having the social intelligence of an AI is seen as a compliment, and people increasingly turn to algorithms for solutions to romantic dilemmas, from analyzing chat histories to crafting responses. The piece then delves into a stark case study involving internet celebrity Han Anran, who was allegedly targeted in an 'AI-powered pig-butchering scam' by her ex-boyfriend. He reportedly used AI to create a detailed, coldly calculated manual from their very first day of dating. This document outlined strategies for emotional manipulation, psychological control, and resource extraction, setting a 10-billion-yuan financial goal over a decade. This incident underscores how AI can systematize deception, turning complex emotional exploitation into a scalable, efficient operation. Beyond high-stakes fraud, the article examines the pervasive, everyday use of AI 'proxy chatting' in dating. People outsource everything from flirty replies to breakup messages to AI, resulting in generic, awkward, and often easily detectable interactions. This 'outsourcing of love' creates a facade of connection while eroding genuine emotional effort and authenticity. While some users see it as a helpful crutch, it often reveals a lack of sincerity and a disrespect for the partner's intelligence. The commentary argues that we are entering a 'love cheating era'. While AI began as a benign tool to compensate for social awkwardness, its misuse is reshaping the rules of engagement. Relationships risk becoming data exchanges between systems, with humans as secondary players. The deeper crisis is not that AI is becoming more human-like, but the growing belief that humans are inferior to AI in providing perfect, calculated responses. The article concludes with a critical reflection: AI itself is amoral; it merely amplifies the intentions of its users. It did not invent deception but has made it more efficient and detached. In a world where affection can be algorithmic and intimacy can be a scam, the piece poses urgent questions: Do we still dare to love a flawed, specific person? And in an age of pervasive 'cheating', are those who offer their awkward, un-augmented genuine selves still worthy of love?"

marsbitHace 17 min(s)

The Top 'Doghead Strategist' in the Blind Date Scene: Doubao

marsbitHace 17 min(s)

Trading

Spot
活动图片