Microsoft Warns of Crypto Clipper Malware Spread by USB Drives and Routed Through Tor

Microsoft Warns of Crypto Clipper Malware Spread by USB Drives and Routed Through Tor

N
News Editor 01
2026-07-24 06:20:17
Microsoft says a crypto clipper campaign active since February 2026 spreads through infected USB drives, steals seed phrases and private keys, swaps wallet addresses, and hides communications through Tor.

Microsoft has disclosed a crypto clipper campaign active since February 2026 that spreads through infected USB drives and steals wallet-related data. In a warning published on June 17, Microsoft Threat Intelligence and Microsoft Defender researchers said the malware captures clipboard contents, replaces cryptocurrency wallet addresses, and sends stolen data through the Tor network, making operator tracing much harder. Microsoft Defender Antivirus detects the threat as Trojan:Win32/CryptoBandits.A.

Malicious shortcut files turn common documents into an infection path

Microsoft said the campaign does not rely on phishing emails or fake download pages. Instead, it uses malicious .lnk shortcut files placed on USB storage devices. The malware scans the drive for common file types such as .doc, .xlsx, and .pdf, hides the original files, and creates lookalike shortcuts using the same names. A user who clicks what appears to be a normal document launches the malware instead.

Once running, the clipper copies itself to any new USB drive connected to the infected system. That gives it worm-like spread between devices, and this stage does not need an internet connection.

Clipboard checks every 500 milliseconds target seed phrases and keys

According to Microsoft, the malware is built to hunt for cryptocurrency data and checks the clipboard about every 500 milliseconds. It looks for 12-word and 24-word BIP39 seed phrases as well as Ethereum and Bitcoin WIF private keys. Captured data is stored locally first, then sent out through Tor, with the local copy deleted only after transmission succeeds.

The most dangerous function is wallet address substitution. When a victim copies an address before sending funds, the malware silently replaces it with an attacker-controlled address. Microsoft said the substituted address is made to resemble the original by matching certain leading or trailing characters across formats including Bitcoin, Tron, and Monero.

Hidden Tor client masks traffic and supports remote code execution

Microsoft’s analysis said the malware launches a renamed portable Tor client, ugate.exe, in a hidden window. It then waits about 60 seconds for Tor to initialize before registering the infected device with a hidden-service command server using a unique victim ID. All communications are routed through localhost:9050, a local Tor proxy, leaving defenders without a public IP address to block.

The malware also includes simple anti-analysis behavior. If Task Manager is running, it shuts down immediately. Beyond text theft, it captures five screenshots at intervals of 10 seconds and uploads them asynchronously through Tor. Microsoft added that if the command server returns an “EVAL” instruction, the malware executes arbitrary code on the infected machine at once, extending the threat from wallet theft to remote control.

Microsoft’s recommended defenses

Microsoft said behavioral detection is more useful than static file signatures against this campaign because the malware is heavily obfuscated. The company recommends disabling AutoRun and AutoPlay for removable media, blocking execution of .lnk files from removable drives through Group Policy, restricting unnecessary use of wscript.exe and cscript.exe, monitoring for SOCKS5 proxy activity on localhost:9050, and checking systems for clipboard inspection or wallet-address replacement behavior.

For individual wallet users, Microsoft’s guidance is simpler: do not connect unfamiliar USB drives, and verify every pasted wallet address character by character before confirming a transfer. Microsoft said the campaign ran from February until public disclosure, leaving about a four-month window in which many victims may have been infected without realizing it.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.