Microsoft Threat Intelligence has identified a sophisticated Windows-based cryptocurrency clipper malware, active since February 2026, that uses Tor-routed communications to steal digital assets and execute remote commands.
Key Points
- The malware spreads via malicious .lnk shortcuts on USB drives, deploying a worm component for propagation and a stealer component for data harvesting.
- It monitors the clipboard every 500 milliseconds to intercept cryptocurrency seed phrases, private keys, and wallet addresses for real-time substitution.
- Attackers utilize a bundled Tor client and local SOCKS5 proxy on port 9050 to communicate with hidden-service command-and-control servers anonymously.
- The threat includes remote code execution capabilities, allowing attackers to push arbitrary scripts to compromised systems via an EVAL command.
- Microsoft Defender detects the threat as Trojan:Win32/CryptoBandits.A and identifies suspicious behaviors like unauthorized PowerShell screen captures and script-based data exfiltration.