Key facts
- Microsoft has detailed a new cryptocurrency clipper malware campaign targeting Windows users since February 2026.
- The malware, referred to as CryptoBandits, spreads via malicious Windows Shortcut (LNK) files distributed on USB drives.
- It intercepts clipboard data to steal cryptocurrency credentials and substitutes wallet addresses with attacker-controlled ones.
- The malware utilizes a portable Tor client to communicate with hidden .onion services, acting as a lightweight backdoor.
- It also exfiltrates screenshots and can execute remote code supplied by the command-and-control server.
Microsoft has detailed a sophisticated Windows-based cryptocurrency clipper malware campaign, dubbed CryptoBandits, that has been targeting users since February 2026. The malware employs self-spreading capabilities via USB drives and utilizes the Tor anonymity network to communicate with hidden command-and-control servers.
