Microsoft warns crypto clipper campaign uses Tor and worm-like spread

Microsoft warns crypto clipper campaign uses Tor and worm-like spread

Microsoft said the Windows malware has been active since February, spreading through malicious USB shortcut files while hijacking clipboard wallet addresses and stealing seed phrases, private keys and wallet data.

BTC
ETH

Fact Check
The primary Microsoft Security Blog post (June 17, 2026) directly confirms the claim: a Windows crypto clipper active since February 2026, spreading through malicious .lnk shortcut files on USB drives with worm-like propagation, swapping wallet addresses, and stealing wallet credentials (BIP39 seed phrases and private keys), while using Tor for C2. The crypto.news report corroborates these details. Every element of the claim matches the authoritative source.
    Reference12
Summary

Microsoft warned that a Windows cryptocurrency-stealing trojan dubbed CryptoBandits has been active since February, spreading through malicious USB shortcut files while targeting wallet users. The malware monitors clipboard activity, replaces copied wallet addresses with attacker-controlled ones during transfers, and steals sensitive wallet data including 12- or 24-word BIP39 seed phrases, Ethereum keys and Bitcoin WIF-format private keys. Microsoft said the threat, detected as Trojan:Win32/CryptoBandits.A, also uses a built-in Tor client for concealed command-and-control communications, persists through scheduled tasks, excludes itself from Microsoft Defender scans and can capture repeated screenshots, making it a more sophisticated clipper operation with worm-like behavior.

Terms & Concepts
  • Tor: A privacy network used to conceal internet traffic and the location of connected services.
  • BIP39 seed phrases: Standard 12- or 24-word recovery phrases that can restore access to a crypto wallet.
  • command-and-control: The remote infrastructure attackers use to send instructions to and receive data from infected devices.