Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

Newly discovered CryptoBandits malware revives worm-like USB propagation, hijacks crypto transactions, and uses the Tor network to evade detection and maintain persistence.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 19, 2026
in Security & Hacks
0 0
Microsoft Uncovers Crypto Malware That Spreads Like a Worm and Hides Behind Tor

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Microsoft has detailed a newly discovered malware campaign that combines several techniques rarely seen together in modern cybercrime operations, reviving the tactics of old USB-borne worms while targeting one of today’s most lucrative assets: cryptocurrency. The campaign, which Microsoft researchers have tracked since February 2026, revolves around a piece of malware known as a “crypto clipper.” Such malware is designed to intercept cryptocurrency transactions by replacing wallet addresses copied to a victim’s clipboard. However, researchers say this campaign goes far beyond a typical clipper operation.

According to Microsoft’s analysis, the malware is capable of spreading through removable storage devices, maintaining long-term persistence on infected systems, and communicating with attackers through the Tor anonymity network. The combination has led researchers to classify it as a more sophisticated threat than the average cryptocurrency-stealing malware. Microsoft Defender detects it as Trojan/CryptoBandits.A.A.

Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…

— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026

A USB Infection Method That Resembles Older Worm Campaigns

One of the most unusual aspects of the campaign is how it spreads. While most contemporary malware relies on phishing emails, malicious advertisements, or compromised software downloads, this operation uses removable USB drives as a propagation mechanism.

Microsoft found that the malware hides legitimate files stored on a USB device and replaces them with shortcut files designed to appear identical to the originals. When a user opens what appears to be a document, the shortcut launches malicious scripts in the background while preserving the illusion that the intended file was opened normally.

Researchers noted that the malware is capable of copying itself onto newly connected removable drives, allowing it to move from one machine to another without relying on internet-based distribution. This worm-like behavior echoes techniques widely used by malware families more than a decade ago but is now rarely observed in campaigns focused on cryptocurrency theft. The approach gives attackers a reliable way to spread inside environments where users frequently exchange files through portable storage devices.

The campaign also reflects a broader trend in Microsoft’s recent threat intelligence findings. Researchers have increasingly observed attackers combining traditional infection techniques with modern infrastructure and automation tools to improve success rates. Similar patterns have appeared in recent phishing operations that leveraged advanced technologies to target organizations at scale.

More Than a Cryptocurrency Clipper

Once installed, the malware begins monitoring the system for cryptocurrency-related activity. Its primary objective remains financial theft. The malware continuously monitors the clipboard every 500 milliseconds and searches for cryptocurrency wallet addresses. When a victim copies a wallet address to send funds, the malware can replace it with an address controlled by the attacker.

The replacement process is sophisticated. It creates similar-looking wallet addresses by matching the first few or last characters of legitimate addresses, particularly for Bitcoin Legacy, P2SH, Taproot, Tron, Monero, and other popular cryptocurrencies. This makes the swap harder for users to notice before confirming a transaction. Because blockchain transactions are generally irreversible, funds sent to an attacker’s wallet are often impossible to recover.

Microsoft’s investigation found that the malware also searches for wallet recovery phrases, private keys, and other cryptocurrency-related credentials. Researchers observed screenshot-capturing functionality that takes multiple screenshots at 10-second intervals, suggesting the operators are interested in gathering additional information from compromised devices. The malware stores much of its functionality in encrypted form and uses obfuscated JavaScript components to make analysis more difficult. Microsoft also noted that some modules contain checks designed to identify security tools or analysis environments, including Task Manager, helping the malware avoid detection.

These capabilities indicate that the campaign is not limited to simple clipboard manipulation. Instead, it appears designed to establish continued access while maximizing opportunities for cryptocurrency theft. The malware also supports remote code execution through “EVAL” commands received from its command-and-control infrastructure.

Tor Infrastructure Raises Additional Concerns

Perhaps the most significant finding in Microsoft’s report is the campaign’s use of the Tor network. The malware launches a renamed Tor binary called “ugate.exe” and connects to hidden services hosted within Tor. This provides attackers with an additional layer of anonymity and makes infrastructure tracking significantly more difficult. Researchers observed that infected systems could receive commands from operators, download additional payloads, and execute tasks remotely. While Microsoft has not described the malware as a full-featured remote access trojan, the command capabilities suggest operators can expand their activities beyond clipboard hijacking if needed.

The use of Tor also complicates defensive efforts. Security teams can often identify and block known command-and-control infrastructure, but hidden services are considerably harder to attribute and disrupt. Security experts note that reducing the impact of threats like CryptoBandits requires more than endpoint protection alone. Strong access controls, device management policies, and operational security practices can help organizations limit the spread of malware and prevent unauthorized access to sensitive systems and cryptocurrency-related assets.

For Microsoft researchers, the campaign highlights an emerging trend in cybercrime. Rather than relying on a single technique, attackers are increasingly combining older propagation methods, credential theft capabilities, persistence mechanisms, and anonymous communications infrastructure into modular operations that can remain active for extended periods.

Microsoft has released detections and mitigation guidance for customers, but the company has not indicated whether the infrastructure behind the campaign has been dismantled. As a result, security researchers continue to treat the operation as an active threat. The discovery serves as a reminder that even as cybercriminals pursue new opportunities in cryptocurrency, they are often willing to revive older attack methods if those techniques still provide a path into targeted systems. In this case, a tactic once associated with USB worms has been adapted for an era increasingly shaped by digital assets.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: crypto security

Related Posts

US Lawmakers Unveil Stop Crypto ATM Scams Act
Policy & Regulation

US Lawmakers Unveil Stop Crypto ATM Scams Act After Americans Lose $333M to Fraud

by Saravana Kumar Mahendran
June 15, 2026

U.S. lawmakers are seeking tougher safeguards for cryptocurrency ATMs after fraud losses tied to the machines surged across the country,...

Read moreDetails
US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

June 13, 2026
U.S. Authorities Bust Major Crypto Laundering Ring ‘AudiA6’ in International Operation

U.S. Authorities Bust Major Crypto Laundering Ring ‘AudiA6’ in International Operation

June 12, 2026
How Claude Fable 5 Stopped Our Ethereum USDT Exploit Research by Falling Back to Opus 4.8

How Claude Fable 5 Stopped Our Ethereum USDT Exploit Research by Falling Back to Opus 4.8

June 10, 2026
South Korean Police Open First Investigation into Polymarket Users for Alleged Illegal Gambling

South Korean Police Open First Investigation into Polymarket Users for Alleged Illegal Gambling

June 5, 2026
Radiant Capital Shuts Down Development Following 18-Month Post-Hack Struggle

Radiant Capital Shuts Down Development Following 18-Month Post-Hack Struggle

June 2, 2026
Vitalik Buterin

Vitalik Buterin Proposes AI-Assisted Formal Verification as the Final Form of Secure Software Development

May 19, 2026
Next Post
Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Recommended

  • All
  • News
Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

June 19, 2026
Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

June 19, 2026
Microsoft Uncovers Crypto Malware That Spreads Like a Worm and Hides Behind Tor

Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

June 19, 2026
Renaiss Raises $1.5 Million Led by YZi Labs to Expand On-Chain Infrastructure for Collectible Assets

Renaiss Raises $1.5 Million Led by YZi Labs to Expand On-Chain Infrastructure for Collectible Assets

June 19, 2026
Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

June 19, 2026
Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

June 19, 2026
Microsoft Uncovers Crypto Malware That Spreads Like a Worm and Hides Behind Tor

Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

June 19, 2026
Renaiss Raises $1.5 Million Led by YZi Labs to Expand On-Chain Infrastructure for Collectible Assets

Renaiss Raises $1.5 Million Led by YZi Labs to Expand On-Chain Infrastructure for Collectible Assets

June 19, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges
  • Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees
  • Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.