Microsoft Identifies New Crypto Malware Targeting Wallet Addresses and Private Keys

TheNewsCryptoPublished on 2026-06-19Last updated on 2026-06-19

Abstract

In February 2026, Microsoft identified a new crypto clipper malware, dubbed Trojan/CryptoBandits.A, targeting Windows systems. The malware spreads via malicious shortcut files on USB drives and operates without a traditional installer or control servers by leveraging Windows Script Host and ActiveX to deploy a Tor proxy. Once active, it runs two modules: one for spreading and another for stealing information. The malware continuously monitors the clipboard for 12 or 24-word recovery phrases, Bitcoin/Ethereum private keys, and wallet addresses. When a user copies a wallet address, the malware silently swaps it with one controlled by attackers to divert funds. It also captures screenshots to gather information on wallet balances and user activity, sending data through Tor connections. Additional capabilities include remote code execution and persistence via scheduled tasks. Microsoft advises disabling auto-run features, restricting script interpreters and executable shortcuts from USB drives, and monitoring for suspicious activities like JavaScript execution, localhost:9050 proxy use, PowerShell screenshot capture, and clipboard monitoring.

In February 2026, Microsoft Threat Intelligence and Microsoft Defender Experts found a crypto clipper attack. This was a campaign that was constructed on Windows. The malware exploits cryptocurrency holders through clipboard hijacking and searches for sensitive wallet information. These were reported by Microsoft through their blog.

Attackers primarily spread this malware through malicious .lnk shortcut files distributed on USB drives.The activation of this malicious code leads to the release of two modules by the malware. One module spreads the malware across systems, while the other operates as a clipper and information stealer. Microsoft Defender Antivirus identifies the threat as Trojan/CryptoBandits.A.

Unlike most malware operations, this one does not require the use of an installer or any control servers since it uses the Windows Script Host and ActiveX technology to launch a packaged Tor proxy. It then uses a SOCKS5 proxy on the infected computer and then connects to the control servers, which run on Tor Hidden Service.

Malware Snatches Wallet Information and Swaps Addresses

Following the infection of the system, the malware constantly tracks any clipboard content and looks for recovery phrases, private keys, and wallet addresses. According to Microsoft, the malware targets precisely 12-word and 24-word recovery phrases, Bitcoin private keys, and Ethereum private keys. It swaps the copied wallet addresses with ones controlled by the attackers before users finish their transactions.

The malware takes screenshots and sends them via Tor connections, which allows the attackers to get more information on wallet balances and activities of users. Also, Microsoft stated that the malware has the ability of remote code execution, giving the attackers the possibility to send additional instructions while ensuring persistence through the use of scheduled tasks and encryption of malicious parts of the malware.

Researchers identified several indicators of compromise, including suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommended that organizations disable auto-run features. They would also limit script interpreters and executable shortcuts from USB drives, and monitor any suspicious activity related to this. This malware campaign underscores the continued growth of cryptocurrency usage among investors and users.

Highlighted Crypto News:

Ethereum Foundation Faces Another Departure as Hsiao-Wei Wang Steps Down

TagsBlockchainCryptoCryptocurrencyMalwareMicrosoftWallet

Related Questions

QWhat type of cyber attack did Microsoft identify in February 2026, and what does this malware specifically target?

AMicrosoft identified a crypto clipper attack. The malware targets cryptocurrency holders by hijacking their clipboards to steal sensitive wallet information, including recovery phrases, private keys, and wallet addresses.

QHow does the described malware initially spread to systems, and what is its primary method of operation?

AThe malware initially spreads through malicious .lnk shortcut files distributed on USB drives. Its primary method of operation is clipboard hijacking, where it monitors and swaps copied cryptocurrency wallet addresses with ones controlled by the attackers.

QWhat is unique about the command-and-control (C2) infrastructure of this malware campaign according to the article?

AUnlike most malware, it does not require an installer or traditional control servers. Instead, it uses Windows Script Host and ActiveX to launch a packaged Tor proxy, establishes a SOCKS5 proxy on the infected computer, and connects to control servers running as Tor Hidden Services.

QBesides clipboard monitoring, what other malicious capabilities does this malware possess?

ABeyond clipboard monitoring, the malware can take screenshots and send them via Tor connections, execute remote code, and ensure persistence on the infected system through scheduled tasks and encryption of its malicious components.

QWhat specific indicators of compromise (IoCs) and defensive measures does Microsoft recommend in response to this threat?

AIndicators of compromise include suspicious JavaScript execution, localhost:9050 proxy activity, PowerShell-based screenshot capture, and clipboard monitoring behavior. Microsoft recommends disabling auto-run features, limiting script interpreters and executable shortcuts from USB drives, and monitoring for related suspicious activity.

Related Reads

The Philadelphia Semiconductor Index Tumbles Nearly 5% in a Single Night, Optical and Memory Sectors 'Collapse' Together: Surging U.S. Bond Yields Shake AI Belief

On the evening of August 18th, the US stock market saw a sharp sell-off concentrated in the AI hardware sector, with the Philadelphia Semiconductor Index plummeting nearly 5%. Leading AI infrastructure and components companies in fields like optical communication and memory chips experienced some of the steepest declines, such as Fabrinet (-19.38%) and Kioxia ADR (-13%). The sell-off was not broad-based but rather targeted the long-duration, high-momentum stocks previously driven by AI narrative optimism. This market shift is primarily attributed to a significant surge in long-term US Treasury yields, with the 30-year yield hitting its highest level since 2007. Rising yields increase discount rates, disproportionately impacting the valuations of growth stocks whose profits are projected far into the future—a category that includes most AI hardware plays. Additional pressure came from climbing oil prices due to Middle East tensions, which fueled inflation concerns. The article identifies three structural reasons for the severity of the drop in these specific subsectors: excessive prior gains and crowded positioning, high sensitivity to the sustainability of AI capital expenditure narratives, and inherent high volatility within the supply chain. Importantly, the sell-off appears to be a valuation and positioning reset rather than a fundamental repudiation of AI, evidenced by the relatively modest decline in a bellwether like Nvidia (-2.34%). Looking ahead, the direction hinges on three key indicators: whether the 30-year Treasury yield stabilizes, the trajectory of oil prices and geopolitical risks, and the market's pricing of new AI-related corporate debt. For related Asian and A-share markets, short-term negative sentiment spillover is expected, but medium-term drivers like domestic cloud capex may provide divergence. The episode signifies a market transition from pricing AI's "story" to rigorously evaluating its returns against a backdrop of higher financing costs.

marsbit25m ago

The Philadelphia Semiconductor Index Tumbles Nearly 5% in a Single Night, Optical and Memory Sectors 'Collapse' Together: Surging U.S. Bond Yields Shake AI Belief

marsbit25m ago

Ten Years, Wang Xingxing's Comeback: Unitree Valued at 400 Billion

Over a decade ago, Wang Xingxing, a 29-year-old with a passion for robotics but little funding, demonstrated his struggling robot dog to investors in Hangzhou. In 2019, with his company Unitree nearly out of cash, he captured the attention of Sequoia Capital China's managing director Li Yannan. Despite initial skepticism about the niche market for robot dogs, Wang's vision and deep technical conviction led Sequoia to make an initial seed investment. This marked a turning point. Following Sequoia's lead, a wave of prominent investors including Meituan, Tencent, Alibaba, and various venture capital and state-backed funds joined subsequent funding rounds. Wang's relentless focus and Unitree's technological advancements propelled the company to become a global leader in humanoid robotics. On August 19th, 2027, Unitree Robotics debuted on Shanghai's STAR Market as the first listed humanoid robotics company in China. Its shares skyrocketed over 500% at opening, reaching a market valuation of approximately 400 billion yuan. Wang Xingxing became one of the wealthiest individuals of his generation on the exchange, while Sequoia China, having invested across multiple rounds, remained a major shareholder. The story is celebrated as a classic outlier's triumph—a founder without elite credentials achieving success through pure belief and perseverance. Unitree's IPO is seen as a major milestone for China's embodied AI industry, providing a valuation benchmark and accelerating the sector's maturation. As Wang once stated, he aims to be "a small boat riding the mighty torrent of technology." His journey symbolizes the beginning of a new narrative for Chinese robotics on the global stage.

marsbit25m ago

Ten Years, Wang Xingxing's Comeback: Unitree Valued at 400 Billion

marsbit25m ago

Manufacturing's Share Drops Below 25%: Is Hangzhou Unconcerned?

Hangzhou is entering a critical phase of industrial restructuring. While its manufacturing-to-GDP ratio has fallen below 25%, the city is not alarmed. Instead, it is strategically navigating a dual focus: advancing advanced manufacturing and expanding its service sector, particularly producer services. Recently, the city celebrated the IPO of a humanoid robotics company, seen as a milestone in moving beyond its e-commerce era. Simultaneously, it set an ambitious target for its service sector: to exceed 2 trillion yuan in value by 2030, with producer services making up over 60%. Data shows a clear trend: the service sector's share of GDP has risen to 75.3%, while manufacturing's share has declined to around 20.1%. This shift revives the debate on whether a strong service sector weakens a city's manufacturing "foundation." Hangzhou's approach challenges the notion of a fixed manufacturing "red line" near 25%. The city argues that the quality and integration of industries matter more than simple ratios. Its strategy is "using software to drive hardware," leveraging its core strengths in digital economy and producer services—like R&D, software, and supply chain management—to empower and add value to manufacturing. This is embodied by its emerging "AI era" companies, whose innovation in Hangzhou feeds into national industrial chains. The city believes that for a hub like Hangzhou, the key is not merely boosting visible manufacturing output, but strengthening the "invisible" competitive edge provided by high-end producer services, which ultimately determine manufacturing profitability. National policy is also shifting from insisting on a "stable" manufacturing share to acknowledging a "reasonable" range, allowing for quality-focused development. Hangzhou's future industrial blueprint aims for a manufacturing share above 22% of GDP by 2027, coupled with a dominant, high-value service sector. The goal is not to choose between manufacturing and services, but to deeply integrate them, using advanced services as the accelerator for next-generation manufacturing.

marsbit50m ago

Manufacturing's Share Drops Below 25%: Is Hangzhou Unconcerned?

marsbit50m ago

SEC Suddenly Proposes "Regulation Crypto": U.S. Token Fundraising May Become Legal Again

On August 18, the U.S. Securities and Exchange Commission (SEC) proposed a landmark set of permanent rules, "Regulation Crypto Assets," specifically designed for crypto asset investment contracts. The 402-page proposal introduces two registration exemption paths and a groundbreaking safe harbor mechanism, representing the SEC's first dedicated crypto-specific regulatory framework. Two exemption tiers are proposed: a "Startup Exemption" allowing a one-time raise of up to $5 million within four years with basic disclosure requirements, and a "Financing Exemption" permitting raises of up to $75 million every 12 months with stricter obligations, including financial statements and ongoing reporting. Both paths require "principles-based narrative disclosure," a flexible approach distinct from traditional IPO forms. The most transformative element is the investment contract safe harbor. It provides a legal path for tokens to "graduate" from being classified as securities. If an issuer completes or permanently ceases its "essential managerial efforts" as promised in the investment contract and meets specific conditions, it can file with the SEC to have the token exit the securities framework. This creates a novel legal lifecycle where a token can begin as a regulated security for fundraising and later become a non-security asset as the network decentralizes. This move is seen as the SEC pragmatically filling a legislative vacuum, as the stalled CLARITY Act in Congress faces significant delays. The proposal aims to offer a compliant pathway for token offerings within the U.S., countering the trend of projects moving overseas. While currently a proposal open for a 60-day public comment period, it signals a major potential shift from an enforcement-heavy approach toward establishing clearer rules for the crypto industry.

marsbit54m ago

SEC Suddenly Proposes "Regulation Crypto": U.S. Token Fundraising May Become Legal Again

marsbit54m ago

Late Qing County Magistrates' 'Official Debt' and the Crypto World's 'Exchange Listings': The Cross-Temporal Truth of Financializing Power

This article draws parallels between financialization of power in late Qing Dynasty China and the modern cryptocurrency industry. It opens with a staggering contemporary corruption case involving billions, illustrating how official positions control massive cash flows, akin to toll booths. The core analysis focuses on Du Fengzhi, a late Qing county magistrate. His 22-year journey from passing the provincial exam to finally obtaining a post highlights how bureaucratic "qualification" (like a VC investment) doesn't guarantee immediate benefit. Crucially, upon receiving his appointment, Du had to borrow heavily—"official debt"—to cover travel and networking costs to actually assume his position. Lenders, seeing his future post as a revenue-generating asset, offered loans with exorbitant effective interest rates (e.g., borrowing 4000 taels but receiving only 2000), effectively discounting and financializing his future power. Once in office, Du faced immense pressure from both public tax quotas and his crippling private debt. His diaries reveal aggressive, sometimes extreme, tax collection methods (sealing ancestral temples, pressuring local gentry) to meet these demands. The article argues this created a system where public duty and private financial survival became indistinguishable, with corruption evolving from operational necessity to normalized practice. The piece consistently analogizes this to crypto: VC funding as mere "qualification," the costly "listing" process on exchanges, the role of market makers and KOLs as intermediaries akin to local gentry, and the relentless pressure on funded projects to deliver returns—often leading to perpetual pivots, artificial metrics, and ultimately, the extraction of value from retail liquidity. Both systems, it concludes, are driven by the financialization of future potential, trapping individuals in cycles of debt and obligation with limited alternatives for upward mobility.

marsbit1h ago

Late Qing County Magistrates' 'Official Debt' and the Crypto World's 'Exchange Listings': The Cross-Temporal Truth of Financializing Power

marsbit1h ago

Trading

Spot
活动图片