Techub News reported that Microsoft’s threat intelligence team has issued a warning after detecting a new malware strain named Trojan/CryptoBandits. According to the alert, the malware has been active since February 2026. It spreads by infecting USB drives and is triggered through malicious Windows shortcut files.
Clipboard hijacker targets wallet addresses
Microsoft said CryptoBandits is capable of stealing multiple cryptocurrency assets, including Bitcoin and Ethereum. Its core component is a clipboard hijacker that scans wallet addresses copied to the clipboard every 500 milliseconds. When it detects an address, it replaces that address with one controlled by the attacker. The malware also steals BIP39 seed phrases, creating a direct threat to users’ control over their crypto wallets.
Microsoft advised users to verify wallet addresses before making transfers, avoid opening shortcut files from unknown sources, and handle removable storage devices with caution. The information was cited from U.Today.

