logo

New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto

ID: 78f4a90c-ff9c-5737-8647-4b2c2e3ee1e9

STIX ID: report--78f4a90c-ff9c-5737-8647-4b2c2e3ee1e9

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-06-23

Date Updated: 2026-07-17

Author: Deeba Ahmed

...
...

Microsoft Threat Intelligence and Microsoft Defender experts discovered CryptoBandits, a Windows cryptocurrency clipper active since February 2026 that spreads via malicious .lnk shortcuts on USB drives, hides original files, sets Defender exclusions, and persists to monitor clipboards every 500 ms to swap copied wallet addresses and capture seed phrases; it also takes screenshots, includes a bundled Tor client for anonymous C2 via localhost:9050, and exposes endpoints for commands, screenshot upload, and file download, giving attackers remote control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.