Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Microsoft warns crypto clipper now acts like backdoor

Microsoft warns crypto clipper now acts like backdoor

Crypto.NewsCrypto.News2026/06/18 11:12
By:Crypto.News

Microsoft Threat Intelligence has warned of a Windows-based crypto clipper campaign that has affected users since February 2026.

Summary
  • Microsoft says CryptoBandits uses Tor-routed communication, wallet replacement, screenshots, and remote code execution on Windows.
  • The malware spreads through malicious shortcut files and creates more infected shortcuts from legitimate files.
  • Security teams should hunt linked behaviors, not isolated s, to catch this attack chain early.

In a Microsoft blog, researchers said the malware steals clipboard data, replaces wallet addresses, and searches for valuable crypto information.

The company said Microsoft Defender Antivirus detects the threat as Trojan:Win32/CryptoBandits.A. In an X post, Microsoft said the campaign combines clipboard theft, wallet address replacement, worm-like behavior, and Tor-based communication.

Malware spreads through shortcut files

Microsoft said the attack starts with malicious .lnk shortcut files. These files can arrive through USB storage devices and launch a worm component on infected Windows systems. Once active, the malware creates more malicious shortcuts from legitimate files found on the device.

Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…

— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026

The worm also sets up scheduled tasks for persistence. This allows the malware to keep running after restart and gives attackers a longer window to monitor the device. Microsoft said the threat uses script-based tools rather than a large installer, making simple file-based detection harder.

Tor hides command traffic

The clipper deploys a portable Tor client and routes traffic through a local SOCKS5 proxy. Microsoft said the malware uses localhost:9050 and .onion command-and-control domains to reduce normal DNS visibility and make blocking harder.

The malware checks the clipboard about every 500 milliseconds. It looks for seed phrases, private keys, and crypto wallet addresses. If it finds a wallet address, it can replace it with an attacker-controlled address. If it finds a seed phrase or private key, it can send the data through Tor.

Backdoor features raise risk

Microsoft said the campaign goes beyond basic wallet address switching. The malware can upload screenshots, contact a hidden command server, and run attacker-supplied code through an EVAL command. That turns a crypto stealer into a lightweight backdoor.

The company said, “defenders should hunt for correlated behaviors rather than investigate isolated events.” It advised teams to watch for script engines launching curl, cmd.exe, PowerShell, or unexpected files, especially when paired with localhost:9050 traffic.

Crypto users remain frequent targets

As crypto.news reported earlier, StilachiRAT also targeted crypto wallets and monitored clipboard activity. That Microsoft-linked warning covered malware that could scan browser wallets and extract stored data.

According to an earlier crypto.news report, SparkCat malware used image scanning to search for wallet seed phrases in screenshots. crypto.news previously reported that Binance warned about clipper malware that replaced copied wallet addresses with attacker-controlled ones.

The new Microsoft report shows that clipper malware is becoming more layered. It no longer only waits for users to copy a wallet address. It can spread, hide traffic through Tor, steal wallet data, capture screens, and keep access to the system.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Micron's earnings report dazzles, but stock price remains "unmoved"! Wall Street remains optimistic, with the highest target price set at $1,625

Micron's performance and guidance were both strong, but its share price has already surged 237% this year, resulting in a muted pre-market reaction. Wall Street giants such as Deutsche Bank, Bank of America, Goldman Sachs, and JPMorgan remain collectively bullish—26 long-term strategic customer agreements have secured visibility for profits. UBS has even set a top target price of $1,625, strongly affirming Micron's cross-cycle profitability and robust upside potential.

华尔街见闻•2026/10/01 12:41

US Stock Market Preview | Three Major Index Futures Rise Together, 10-Year US Treasury Yield Hits Highest Since 2002, Micron (MU.US) Experiences Volatility After Earnings

Before the U.S. stock market opens on Thursday, October 1st, all three major U.S. stock index futures are rising.

智通财经•2026/10/01 12:30

Rumor: TSMC (TSM.US) Plans New Texas Campus with Multiple Chip Factories, Total Investment May Reach Tens of Billions of USD

TSMC is considering investing billions of dollars to build more AI chip campuses in Texas.

智通财经•2026/10/01 12:30