Microsoft Discloses Crypto Clipper Trojan, Active Since February 2026

According to Microsoft Security Blog on June 19, Microsoft security researchers discovered a new cryptocurrency-stealing trojan called Crypto Clipper active since February 2026. The malware spreads via USB devices using malicious .lnk shortcuts to infect Windows users, featuring a built-in Tor client for covert C2 communication. Its capabilities include continuous clipboard monitoring, theft of recovery phrases and private keys, cryptocurrency address replacement, and screen capture uploads, with worm-like self-propagation that automatically hides original USB documents and creates malicious shortcuts.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments