
Microsoft said the Windows malware has been active since February, spreading through malicious USB shortcut files while hijacking clipboard wallet addresses and stealing seed phrases, private keys and wallet data.
Microsoft warned that a Windows cryptocurrency-stealing trojan dubbed CryptoBandits has been active since February, spreading through malicious USB shortcut files while targeting wallet users. The malware monitors clipboard activity, replaces copied wallet addresses with attacker-controlled ones during transfers, and steals sensitive wallet data including 12- or 24-word BIP39 seed phrases, Ethereum keys and Bitcoin WIF-format private keys. Microsoft said the threat, detected as Trojan:Win32/CryptoBandits.A, also uses a built-in Tor client for concealed command-and-control communications, persists through scheduled tasks, excludes itself from Microsoft Defender scans and can capture repeated screenshots, making it a more sophisticated clipper operation with worm-like behavior.