OKX Banner
BTC $63,013.00 (-0.38%)
ETH $1,698.79 (-1.41%)
BNB $576.73 (-0.92%)
XRP $1.13 (-1.36%)
SOL $68.96 (-1.48%)
TRX $0.32 (+0.52%)
HYPE $68.88 (+1.44%)
DOGE $0.08 (+0.05%)
RAIN $0.01 (-0.41%)
LEO $9.53 (-0.75%)
ZEC $452.01 (-2.93%)
XLM $0.22 (-9.19%)
ADA $0.16 (-0.80%)
CC $0.15 (-4.32%)
XMR $317.23 (-3.13%)
LINK $7.88 (-0.56%)
LAB $14.82 (-6.69%)
GRAM $1.60 (-2.78%)
BCH $196.22 (-3.39%)
M $2.94 (+0.76%)

USB-Based “Crypto Clipper” Malware Targets Windows Users and Steals Wallet Data, Microsoft Warns

Twitter icon  •  Published 5 hours ago on June 19, 2026  •  Hassan Maishera

Microsoft warns of USB-spreading crypto clipper malware targeting Windows users, stealing wallet seed phrases and hijacking transactions via clipboard monitoring and malicious shortcut files.

USB-Based “Crypto Clipper” Malware Targets Windows Users and Steals Wallet Data, Microsoft Warns

TL;DR

  • Microsoft has warned about a USB-spreading “crypto clipper” malware targeting Windows users since February. 

  • The malware installs via malicious .lnk shortcut files, steals crypto wallet seed phrases and private keys through clipboard monitoring, and can replace copied wallet addresses with attacker-controlled ones. 

Microsoft has identified a new malware campaign spreading through infected USB drives that specifically targets cryptocurrency users on Windows systems, according to a recent security blog post. 

The malware, detected by Microsoft Defender Antivirus as Trojan:Win32/CryptoBandits, has been actively infecting personal computers since February.

Infection Begins Through Malicious USB Shortcut Files

The attack starts with a compromised USB drive containing a malicious Windows shortcut file (.lnk). 

These shortcut files are designed to automatically point the system to hidden malware components when opened.

Once a user plugs in the infected USB drive and clicks the shortcut, a worm-like payload is executed on the system. This malware not only installs itself but also enables persistence and prepares the machine for further propagation.

After installation, the malware runs continuously in the background, focusing on stealing cryptocurrency-related data.

One of its primary techniques is clipboard monitoring. The malware checks the Windows clipboard approximately every 500 milliseconds, looking for sensitive information such as:

  • Crypto wallet seed phrases

  • Private keys for Bitcoin or Ethereum wallets

Once detected, this data is transmitted to attackers through the Tor network, an anonymized communication system that helps conceal command-and-control activity. The malware also captures multiple screenshots of the infected system at timed intervals.

Transaction Hijacking Through Address Replacement

In addition to data theft, the malware performs transaction manipulation. If a user copies a crypto wallet address to send funds, the malware silently replaces it with an attacker-controlled address. 

This means funds can be redirected without any visible indication to the user, making it particularly dangerous for active traders and wallet users.

The malware also spreads using a worm-like mechanism.

When a clean USB drive is connected to an infected system, the malware:

  • Scans files such as Word documents, Excel sheets, and PDFs

  • Replaces them with malicious shortcut files using the same filenames

  • Infects the new drive, continuing the cycle when plugged into another PC

This allows the malware to spread rapidly across offline environments where USB drives are commonly shared.

Microsoft Security Recommendations

Microsoft advises users and organizations to take several precautions to reduce risk, including:

  • Disabling AutoRun for removable media

  • Blocking execution of .lnk files from USB drives using Group Policy

  • Restricting script hosts such as wscript.exe and cscript.exe

  • Monitoring for suspicious Tor network activity, including connections on port 9050

Microsoft Defender customers are also encouraged to run threat-hunting queries using published indicators of compromise, including file hashes and known .onion command-and-control domains.

The campaign highlights a rising trend of malware designed specifically to target cryptocurrency holders by exploiting weak points such as clipboard usage and offline file transfers.

Security researchers warn that the combination of USB-based propagation and real-time clipboard hijacking makes this malware particularly difficult to detect without proactive security controls.

 

Fidelity Launches Government Money Market Fund for Stablecoin Reserves
Next article Fidelity Launches Government Money Market Fund for Stablecoin Reserves
Hassan Maishera

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.