Microsoft Uncovers Windows Crypto Clipper Campaign Using Tor Infrastructure on June 19

According to Microsoft Threat Intelligence and Microsoft Defender Experts, on June 19 the company discovered a Windows-based cryptocurrency clipper malware campaign targeting users since February 2026. The threat spreads via malicious shortcut files (.lnk) on removable USB drives and intercepts wallet addresses, seed phrases, and private keys. The malware uses a bundled Tor proxy to hide network activity and can replace copied cryptocurrency addresses with attacker-controlled ones, redirecting transactions. It also includes remote command execution capabilities and creates scheduled tasks to maintain persistence. Microsoft Defender Antivirus detects related components as Trojan:Win32/CryptoBandits.A.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments