Microsoft Warns CryptoBandits Malware Threatens Crypto Assets

Microsoft Warns CryptoBandits Malware Threatens Crypto Assets

N
News Editor
2026-06-19 08:21:33
Microsoft’s threat intelligence team warned that Trojan/CryptoBandits has been active since February 2026, spreading through infected USB drives and malicious Windows shortcut files while targeting crypto wallets and BIP39 seed phrases.
MicrosoftCryptoBanditsMalwareCrypto SecurityClipboard Hijacker

Techub News reported that Microsoft’s threat intelligence team has issued a warning after detecting a new malware strain named Trojan/CryptoBandits. According to the alert, the malware has been active since February 2026. It spreads by infecting USB drives and is triggered through malicious Windows shortcut files.

Clipboard hijacker targets wallet addresses

Microsoft said CryptoBandits is capable of stealing multiple cryptocurrency assets, including Bitcoin and Ethereum. Its core component is a clipboard hijacker that scans wallet addresses copied to the clipboard every 500 milliseconds. When it detects an address, it replaces that address with one controlled by the attacker. The malware also steals BIP39 seed phrases, creating a direct threat to users’ control over their crypto wallets.

Microsoft advised users to verify wallet addresses before making transfers, avoid opening shortcut files from unknown sources, and handle removable storage devices with caution. The information was cited from U.Today.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.