Microsoft Warns of USB-Spreading Crypto Clipper Targeting Seed Phrases and Private Keys

Microsoft Warns of USB-Spreading Crypto Clipper Targeting Seed Phrases and Private Keys

N
News Editor 01
2026-07-23 21:25:15
Microsoft says a USB-borne crypto clipper active since February can replace wallet addresses, search for BIP39 seed phrases and private keys, and keep remote access through Tor.
Microsoftcybersecuritycrypto walletsmalwareWindows

Microsoft Threat Intelligence has warned that a cryptocurrency-focused malware strain is spreading through USB devices and targeting digital asset holders on Windows. The malware has been active since February, and Microsoft says it does more than hijack copied wallet addresses: it also searches for BIP39 seed phrases and private keys while keeping remote access on infected machines.

USB shortcuts are used to trigger the infection

According to Microsoft, the malware hides legitimate files stored on removable drives and replaces them with deceptive shortcut files. A single click is enough to launch the payload, after which the malware continues propagating to other removable storage connected to the system. The method is simple. The impact is not. For Windows users holding crypto, one mistaken action can expose wallet credentials to attackers.

Clipboard theft expands into seed phrase and key hunting

The threat is categorized as a crypto clipper, but Microsoft says its scope goes beyond clipboard monitoring for wallet addresses. It actively looks for sensitive cryptocurrency data, including copied seed phrases and private keys. That broadens the danger. Attackers are not only trying to redirect transfers; they are also collecting the information needed to access holdings directly and preserve future access to compromised devices.

Tor-based communications help keep operators hidden

Microsoft said the malware drops two heavily obfuscated JavaScript payloads into the Windows Documents directory and creates scheduled tasks to support both propagation and credential theft. It also installs a copy of Tor on the victim device and disguises it under the filename “ugate.exe”. From there, it connects through Tor to onion addresses controlled by the operators, masking the infrastructure behind the campaign.

That setup allows the attackers to maintain remote access without relying on exposed traditional command-and-control servers. Microsoft said operators can issue commands, deliver more malware, or execute arbitrary code through that channel. The malware also captures screenshots every 10 seconds, giving the attackers a steady view of user activity, and swaps copied wallet addresses with attacker-controlled alternatives in Bitcoin, Tron, and Monero transactions.

Detection name and defensive steps

Microsoft Defender Antivirus currently detects the threat as Trojan:Win32/CryptoBandits.A. Microsoft advised users to disable autoplay for removable media, block shortcut execution from USB drives, and watch systems for suspicious scripts and proxy-related activity.

Crypto malware on Windows keeps getting more capable

The warning comes as Windows-based threats aimed at cryptocurrency users grow more sophisticated in 2026. Earlier this month, the Foresiet Threat Intel Team identified another malware strain, Lucid Stealer, built to target browser extensions and crypto wallets. Microsoft’s findings point to the same pattern: crypto malware is moving beyond one-time credential theft and combining wallet-focused attacks with persistence and remote control.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.