ChainCatcher reported that Microsoft’s threat intelligence team has disclosed a Windows-based crypto clipboard trojan threat. According to the information released, the malware has been active since February 2026 and is aimed at users of digital assets.
Microsoft described the malware as combining “worm-like propagation,” “clipboard hijacking” and “Tor anonymous communication.” Clipboard hijacking centers on content copied by users; in a digital asset context, copied addresses and transfer-related information are closely connected with asset movement. Worm-like propagation describes the malware’s ability to spread within affected environments, while Tor anonymous communication is used as part of its communication setup.
The disclosure identifies the active period, attack components and target group of this Windows crypto clipboard trojan. For digital asset users, the notice provides a clearer description of the malware’s operating pattern and the specific combination of techniques involved in the attacks.

