New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto
ID: 78f4a90c-ff9c-5737-8647-4b2c2e3ee1e9
STIX ID: report--78f4a90c-ff9c-5737-8647-4b2c2e3ee1e9
Feed Name: HackRead
Microsoft Threat Intelligence and Microsoft Defender experts discovered CryptoBandits, a Windows cryptocurrency clipper active since February 2026 that spreads via malicious .lnk shortcuts on USB drives, hides original files, sets Defender exclusions, and persists to monitor clipboards every 500 ms to swap copied wallet addresses and capture seed phrases; it also takes screenshots, includes a bundled Tor client for anonymous C2 via localhost:9050, and exposes endpoints for commands, screenshot upload, and file download, giving attackers remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
