Key facts
- Microsoft discovered a new malware called Crypto Clipper that steals cryptocurrency.
- The malware spreads through malicious shortcut files (.lnk) distributed on USB drives.
- It monitors the clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses.
- Crypto Clipper uses Tor for anonymous communication with its command-and-control server.
- The malware also captures screenshots and can execute remote code on infected systems.
Microsoft has identified a new cryptocurrency-stealing malware, dubbed Crypto Clipper, that spreads through malicious shortcut files on USB drives. The malware, active since February 2026, monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. When detected, it replaces copied wallet addresses with ones belonging to attacker-controlled wallets, effectively diverting payments. The malware also captures screenshots and exfiltrates data to attacker-controlled servers through the Tor network, utilizing a portable Tor client and a SOCKS5 proxy for anonymous communication. This approach allows the malware to function as a lightweight backdoor, enabling remote code execution and blending data theft with persistent control over compromised devices. Microsoft Defender for Endpoint detects multiple components of this threat, while Microsoft Defender Antivirus identifies it as Trojan:Win32/CryptoBandits.A.
