Go to app

Technical Details of "CryptoBandits"

Published 6/19/2026, 9:19:27 AM

Microsoft has issued a warning regarding a sophisticated Windows-based "clipper" malware campaign, active since February 2026, that utilizes USB drives to spread like a worm. Identified by Microsoft Defender as Trojan:Win32/CryptoBandits, the malware is designed to hijack cryptocurrency transactions and harvest sensitive wallet credentials [Source: https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/].

Technical Details of "CryptoBandits"

The malware combines traditional clipboard hijacking with advanced evasion and exfiltration techniques to drain user wallets.

Why and How It Spreads

The primary motive is the direct theft of liquid crypto assets. Its rapid spread is attributed to a "worm-like" propagation method:

  1. USB Infection: When an infected computer detects a new USB drive, the malware copies itself to the drive and scans for documents (.doc, .xlsx, .pdf).
  2. Social Engineering: It hides the original documents and replaces them with malicious .lnk (shortcut) files that use the same names and icons. When a user clicks the shortcut on a new computer, the malware executes [Source: https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/].

Malware Capabilities Summary

FeatureDetail
Detection NamesTrojan:Win32/CryptoBandits.A/B, Trojan:JS/CryptoBandits.A/B
Primary GoalTheft of crypto assets via address swapping and seed phrase harvesting
PropagationUSB-based worm using malicious .lnk shortcuts
C2 InfrastructureTor-based hidden services (.onion)
PersistenceScheduled tasks and Windows Defender exclusions

Recommended Mitigations

Microsoft recommends that users disable AutoRun/AutoPlay for removable media and block .lnk file execution from USB drives. Additionally, monitoring for Tor activity on local ports (specifically localhost:9050) can serve as a high-confidence indicator of an active infection [Source: https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/].