Microsoft Identifies New Crypto Malware Targeting Wallet Addresses and Private Keys

TheNewsCryptoPubblicato 2026-06-19Pubblicato ultima volta 2026-06-19

Introduzione

In February 2026, Microsoft identified a new crypto clipper malware, dubbed Trojan/CryptoBandits.A, targeting Windows systems. The malware spreads via malicious shortcut files on USB drives and operates without a traditional installer or control servers by leveraging Windows Script Host and ActiveX to deploy a Tor proxy. Once active, it runs two modules: one for spreading and another for stealing information. The malware continuously monitors the clipboard for 12 or 24-word recovery phrases, Bitcoin/Ethereum private keys, and wallet addresses. When a user copies a wallet address, the malware silently swaps it with one controlled by attackers to divert funds. It also captures screenshots to gather information on wallet balances and user activity, sending data through Tor connections. Additional capabilities include remote code execution and persistence via scheduled tasks. Microsoft advises disabling auto-run features, restricting script interpreters and executable shortcuts from USB drives, and monitoring for suspicious activities like JavaScript execution, localhost:9050 proxy use, PowerShell screenshot capture, and clipboard monitoring.

In February 2026, Microsoft Threat Intelligence and Microsoft Defender Experts found a crypto clipper attack. This was a campaign that was constructed on Windows. The malware exploits cryptocurrency holders through clipboard hijacking and searches for sensitive wallet information. These were reported by Microsoft through their blog.

Attackers primarily spread this malware through malicious .lnk shortcut files distributed on USB drives.The activation of this malicious code leads to the release of two modules by the malware. One module spreads the malware across systems, while the other operates as a clipper and information stealer. Microsoft Defender Antivirus identifies the threat as Trojan/CryptoBandits.A.

Unlike most malware operations, this one does not require the use of an installer or any control servers since it uses the Windows Script Host and ActiveX technology to launch a packaged Tor proxy. It then uses a SOCKS5 proxy on the infected computer and then connects to the control servers, which run on Tor Hidden Service.

Malware Snatches Wallet Information and Swaps Addresses

Following the infection of the system, the malware constantly tracks any clipboard content and looks for recovery phrases, private keys, and wallet addresses. According to Microsoft, the malware targets precisely 12-word and 24-word recovery phrases, Bitcoin private keys, and Ethereum private keys. It swaps the copied wallet addresses with ones controlled by the attackers before users finish their transactions.

The malware takes screenshots and sends them via Tor connections, which allows the attackers to get more information on wallet balances and activities of users. Also, Microsoft stated that the malware has the ability of remote code execution, giving the attackers the possibility to send additional instructions while ensuring persistence through the use of scheduled tasks and encryption of malicious parts of the malware.

Researchers identified several indicators of compromise, including suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommended that organizations disable auto-run features. They would also limit script interpreters and executable shortcuts from USB drives, and monitor any suspicious activity related to this. This malware campaign underscores the continued growth of cryptocurrency usage among investors and users.

Highlighted Crypto News:

Ethereum Foundation Faces Another Departure as Hsiao-Wei Wang Steps Down

TagsBlockchainCryptoCryptocurrencyMalwareMicrosoftWallet

Domande pertinenti

QWhat type of cyber attack did Microsoft identify in February 2026, and what does this malware specifically target?

AMicrosoft identified a crypto clipper attack. The malware targets cryptocurrency holders by hijacking their clipboards to steal sensitive wallet information, including recovery phrases, private keys, and wallet addresses.

QHow does the described malware initially spread to systems, and what is its primary method of operation?

AThe malware initially spreads through malicious .lnk shortcut files distributed on USB drives. Its primary method of operation is clipboard hijacking, where it monitors and swaps copied cryptocurrency wallet addresses with ones controlled by the attackers.

QWhat is unique about the command-and-control (C2) infrastructure of this malware campaign according to the article?

AUnlike most malware, it does not require an installer or traditional control servers. Instead, it uses Windows Script Host and ActiveX to launch a packaged Tor proxy, establishes a SOCKS5 proxy on the infected computer, and connects to control servers running as Tor Hidden Services.

QBesides clipboard monitoring, what other malicious capabilities does this malware possess?

ABeyond clipboard monitoring, the malware can take screenshots and send them via Tor connections, execute remote code, and ensure persistence on the infected system through scheduled tasks and encryption of its malicious components.

QWhat specific indicators of compromise (IoCs) and defensive measures does Microsoft recommend in response to this threat?

AIndicators of compromise include suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommends disabling auto-run features, limiting script interpreters and executable shortcuts from USB drives, and monitoring for related suspicious activity.

Letture associate

Mathematicians Refute Open AI's Claim of Proving Connes Rigidity Conjecture Within 24 Hours: 'AI Proved Every Sentence Correct, but They Are No Longer About the Original Conjecture'

Mathematician Refutes OpenAI's Claim of Disproving Connes Rigidity Conjecture in 24 Hours OpenAI claimed its next-generation AI model solved 10 world-class problems, including disproving the Connes Rigidity Conjecture. The next day, mathematician J. L. Nielsen from the University of Kansas published a paper refuting the AI's counterexample. Nielsen meticulously reviewed OpenAI's publicly released 37,000 lines of Lean 4 code, mapping each object back to its mathematical origin. He identified two independent failure paths in the AI's argument. He concluded that one of the two groups constructed by the AI does not satisfy the required conditions (specifically ICC and Kazhdan's property (T)) necessary to serve as a valid counterexample to the original conjecture. This means the AI may have successfully proven something about its constructed objects, but that statement is not equivalent to disproving the Connes Rigidity Conjecture itself. The incident highlights a crucial limitation of formal verification tools like Lean. While Lean's kernel can verify the logical correctness of a proof's steps, it cannot verify whether the formal statement being proven correctly corresponds to the intended mathematical conjecture. Human oversight remains essential to ensure the alignment between the formalized problem and the original research question. This case exemplifies what researchers call "successfully proving the wrong statement." The Connes Rigidity Conjecture, concerning the uniqueness of group von Neumann algebras under certain conditions, remains an open problem.

marsbit25 min fa

Mathematicians Refute Open AI's Claim of Proving Connes Rigidity Conjecture Within 24 Hours: 'AI Proved Every Sentence Correct, but They Are No Longer About the Original Conjecture'

marsbit25 min fa

When Crypto Assets Become Mortgage Collateral: The Triangular Dilemma of Regulation, Cost, and Tokenized Equity

When Crypto Assets Become Mortgage Collateral: The Trilemma of Regulation, Cost, and Tokenized Rights Better, in partnership with Coinbase, has launched a mortgage solution allowing borrowers to pledge Bitcoin or USDC as collateral. This facilitates two loans: a primary, Fannie Mae-compliant mortgage and a separate private loan for the down payment, secured by the crypto assets and a second lien on the property. The product targets asset-rich but cash-poor buyers, with high collateral requirements (250% for Bitcoin, 125% for USDC) and no margin calls. The initiative has drawn significant regulatory scrutiny. Seven U.S. Senators, led by Dick Durbin and Elizabeth Warren, sent a letter to the FHFA urging a halt, arguing the high collateral ratio itself acknowledges crypto's risk and that combined loan costs could be 1.5 percentage points higher, potentially burdening taxpayers. Despite criticism and Bitcoin's price volatility, Better's CEO Vishal Garg plans to expand support to tokenized equities (e.g., Tesla, SpaceX) and envisions using retirement accounts to help family members buy homes. A core challenge for tokenized assets is clarifying the legal rights conferred by holding such tokens. To reduce costs, Better partnered with Framework Ventures, aiming to lower capital expenses by over 100 basis points and offer sub-5% rates. While the company posted a loss in Q1 2025, it reports strong demand, with a waitlist representing ~$250M in potential loans. Garg remains committed to the model, viewing it as a key channel for integrating digital assets into the banking system.

marsbit35 min fa

When Crypto Assets Become Mortgage Collateral: The Triangular Dilemma of Regulation, Cost, and Tokenized Equity

marsbit35 min fa

Trading

Spot
活动图片