Microsoft Threat Intelligence has warned that a cryptocurrency-focused malware strain is spreading through USB devices and targeting digital asset holders on Windows. The malware has been active since February, and Microsoft says it does more than hijack copied wallet addresses: it also searches for BIP39 seed phrases and private keys while keeping remote access on infected machines.
USB shortcuts are used to trigger the infection
According to Microsoft, the malware hides legitimate files stored on removable drives and replaces them with deceptive shortcut files. A single click is enough to launch the payload, after which the malware continues propagating to other removable storage connected to the system. The method is simple. The impact is not. For Windows users holding crypto, one mistaken action can expose wallet credentials to attackers.
Clipboard theft expands into seed phrase and key hunting
The threat is categorized as a crypto clipper, but Microsoft says its scope goes beyond clipboard monitoring for wallet addresses. It actively looks for sensitive cryptocurrency data, including copied seed phrases and private keys. That broadens the danger. Attackers are not only trying to redirect transfers; they are also collecting the information needed to access holdings directly and preserve future access to compromised devices.
Tor-based communications help keep operators hidden
Microsoft said the malware drops two heavily obfuscated JavaScript payloads into the Windows Documents directory and creates scheduled tasks to support both propagation and credential theft. It also installs a copy of Tor on the victim device and disguises it under the filename “ugate.exe”. From there, it connects through Tor to onion addresses controlled by the operators, masking the infrastructure behind the campaign.
That setup allows the attackers to maintain remote access without relying on exposed traditional command-and-control servers. Microsoft said operators can issue commands, deliver more malware, or execute arbitrary code through that channel. The malware also captures screenshots every 10 seconds, giving the attackers a steady view of user activity, and swaps copied wallet addresses with attacker-controlled alternatives in Bitcoin, Tron, and Monero transactions.
Detection name and defensive steps
Microsoft Defender Antivirus currently detects the threat as Trojan:Win32/CryptoBandits.A. Microsoft advised users to disable autoplay for removable media, block shortcut execution from USB drives, and watch systems for suspicious scripts and proxy-related activity.
Crypto malware on Windows keeps getting more capable
The warning comes as Windows-based threats aimed at cryptocurrency users grow more sophisticated in 2026. Earlier this month, the Foresiet Threat Intel Team identified another malware strain, Lucid Stealer, built to target browser extensions and crypto wallets. Microsoft’s findings point to the same pattern: crypto malware is moving beyond one-time credential theft and combining wallet-focused attacks with persistence and remote control.

