Microsoft Discloses CryptoBandits Trojan Using Tor and Clipboard Wallet Hijacking

Microsoft Discloses CryptoBandits Trojan Using Tor and Clipboard Wallet Hijacking

N
News Editor
2026-06-19 11:48:13
Microsoft’s threat intelligence team has disclosed a Windows crypto trojan active since February 2026. The malware combines worm-like spreading, clipboard hijacking and Tor-based anonymous communications to target digital asset users, steal sensitive data and replace copied cryptocurrency addresses.
MicrosoftCrypto TrojanCryptoBanditsTorWallet SecurityClipboard Hijacking

Odaily reported that Microsoft’s threat intelligence team has officially disclosed a Windows crypto trojan threat targeting digital asset users. According to Microsoft, the malware has been active since February 2026 and combines three core capabilities: worm-like propagation, clipboard hijacking and anonymous communication through Tor. This combination allows the threat to spread through devices and removable storage while also interfering with the moment when a user copies a cryptocurrency address for a transfer.

Disguised .lnk Files and a Local Tor Connection

Microsoft’s analysis states that the malicious program spreads between removable storage devices through disguised shortcut files with the .lnk extension. It uses WScript and ActiveX to execute script logic, then automatically deploys a local Tor client. The malware connects through a 127.0.0.1:9050 proxy to a .onion hidden-service C2 server, enabling anonymous command-and-control activity and data return. The attack chain links local script execution, proxy traffic and hidden-service infrastructure into a single control channel.

Clipboard Monitoring, Address Replacement and Data Theft

The trojan includes several malicious functions. It continuously monitors clipboard contents, steals mnemonic phrases and private keys, uploads screenshots, and performs address replacement when a user copies a cryptocurrency address. In that step, the intended wallet address is swapped for an address controlled by the attacker, causing funds to be sent to the wrong destination. The behavior directly targets a common digital-asset transfer workflow in which users copy and paste wallet addresses before confirming transactions.

Microsoft also said the malware has worm-like propagation capabilities. It can copy itself automatically to USB drives and other devices, and it creates scheduled tasks to maintain persistence on the infected Windows system. Its basic anti-analysis behavior includes checking for Task Manager in order to avoid debugging and analysis. On the detection side, Microsoft has classified the threat as part of the Trojan:Win32/CryptoBandits family. The company is blocking it through behavioral indicators including abnormal WScript calls, localhost:9050 proxy traffic and PowerShell screenshot activity. Security researchers recommend focusing defenses on script execution paths and monitoring abnormal local proxy traffic.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.