Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Microsoft Warns of CryptoBandits Malware Using USB Worm Tactics and Tor Network

Newly discovered CryptoBandits malware revives worm-like USB propagation, hijacks crypto transactions, and uses the Tor network to evade detection and maintain persistence.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 19, 2026
in Security & Hacks
0 0
Microsoft Uncovers Crypto Malware That Spreads Like a Worm and Hides Behind Tor

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Microsoft has detailed a newly discovered malware campaign that combines several techniques rarely seen together in modern cybercrime operations, reviving the tactics of old USB-borne worms while targeting one of today’s most lucrative assets: cryptocurrency. The campaign, which Microsoft researchers have tracked since February 2026, revolves around a piece of malware known as a “crypto clipper.” Such malware is designed to intercept cryptocurrency transactions by replacing wallet addresses copied to a victim’s clipboard. However, researchers say this campaign goes far beyond a typical clipper operation.

According to Microsoft’s analysis, the malware is capable of spreading through removable storage devices, maintaining long-term persistence on infected systems, and communicating with attackers through the Tor anonymity network. The combination has led researchers to classify it as a more sophisticated threat than the average cryptocurrency-stealing malware. Microsoft Defender detects it as Trojan/CryptoBandits.A.A.

Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…

— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026

A USB Infection Method That Resembles Older Worm Campaigns

One of the most unusual aspects of the campaign is how it spreads. While most contemporary malware relies on phishing emails, malicious advertisements, or compromised software downloads, this operation uses removable USB drives as a propagation mechanism.

Microsoft found that the malware hides legitimate files stored on a USB device and replaces them with shortcut files designed to appear identical to the originals. When a user opens what appears to be a document, the shortcut launches malicious scripts in the background while preserving the illusion that the intended file was opened normally.

Researchers noted that the malware is capable of copying itself onto newly connected removable drives, allowing it to move from one machine to another without relying on internet-based distribution. This worm-like behavior echoes techniques widely used by malware families more than a decade ago but is now rarely observed in campaigns focused on cryptocurrency theft. The approach gives attackers a reliable way to spread inside environments where users frequently exchange files through portable storage devices.

Related Story

Ledger Researchers Disclose Tangem Card Flaw

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

July 10, 2026 - Updated on July 16, 2026
Hackers Target Injective Wallet Keys Through Compromised npm Package

Malicious Injective SDK Package Targets Private Keys and Seed Phrases

July 10, 2026

The campaign also reflects a broader trend in Microsoft’s recent threat intelligence findings. Researchers have increasingly observed attackers combining traditional infection techniques with modern infrastructure and automation tools to improve success rates. Similar patterns have appeared in recent phishing operations that leveraged advanced technologies to target organizations at scale.

More Than a Cryptocurrency Clipper

Once installed, the malware begins monitoring the system for cryptocurrency-related activity. Its primary objective remains financial theft. The malware continuously monitors the clipboard every 500 milliseconds and searches for cryptocurrency wallet addresses. When a victim copies a wallet address to send funds, the malware can replace it with an address controlled by the attacker.

The replacement process is sophisticated. It creates similar-looking wallet addresses by matching the first few or last characters of legitimate addresses, particularly for Bitcoin Legacy, P2SH, Taproot, Tron, Monero, and other popular cryptocurrencies. This makes the swap harder for users to notice before confirming a transaction. Because blockchain transactions are generally irreversible, funds sent to an attacker’s wallet are often impossible to recover.

Microsoft’s investigation found that the malware also searches for wallet recovery phrases, private keys, and other cryptocurrency-related credentials. Researchers observed screenshot-capturing functionality that takes multiple screenshots at 10-second intervals, suggesting the operators are interested in gathering additional information from compromised devices. The malware stores much of its functionality in encrypted form and uses obfuscated JavaScript components to make analysis more difficult. Microsoft also noted that some modules contain checks designed to identify security tools or analysis environments, including Task Manager, helping the malware avoid detection.

These capabilities indicate that the campaign is not limited to simple clipboard manipulation. Instead, it appears designed to establish continued access while maximizing opportunities for cryptocurrency theft. The malware also supports remote code execution through “EVAL” commands received from its command-and-control infrastructure.

Tor Infrastructure Raises Additional Concerns

Perhaps the most significant finding in Microsoft’s report is the campaign’s use of the Tor network. The malware launches a renamed Tor binary called “ugate.exe” and connects to hidden services hosted within Tor. This provides attackers with an additional layer of anonymity and makes infrastructure tracking significantly more difficult. Researchers observed that infected systems could receive commands from operators, download additional payloads, and execute tasks remotely. While Microsoft has not described the malware as a full-featured remote access trojan, the command capabilities suggest operators can expand their activities beyond clipboard hijacking if needed.

The use of Tor also complicates defensive efforts. Security teams can often identify and block known command-and-control infrastructure, but hidden services are considerably harder to attribute and disrupt. Security experts note that reducing the impact of threats like CryptoBandits requires more than endpoint protection alone. Strong access controls, device management policies, and operational security practices can help organizations limit the spread of malware and prevent unauthorized access to sensitive systems and cryptocurrency-related assets.

For Microsoft researchers, the campaign highlights an emerging trend in cybercrime. Rather than relying on a single technique, attackers are increasingly combining older propagation methods, credential theft capabilities, persistence mechanisms, and anonymous communications infrastructure into modular operations that can remain active for extended periods.

Microsoft has released detections and mitigation guidance for customers, but the company has not indicated whether the infrastructure behind the campaign has been dismantled. As a result, security researchers continue to treat the operation as an active threat. The discovery serves as a reminder that even as cybercriminals pursue new opportunities in cryptocurrency, they are often willing to revive older attack methods if those techniques still provide a path into targeted systems. In this case, a tactic once associated with USB worms has been adapted for an era increasingly shaped by digital assets.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: crypto security

Related Posts

Ledger Researchers Disclose Tangem Card Flaw
Security & Hacks

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

by Saravana Kumar Mahendran
July 10, 2026 - Updated on July 16, 2026

Ledger’s security research unit has disclosed a physical attack that can reset the password on a Tangem hardware wallet card,...

Read moreDetails
Hackers Target Injective Wallet Keys Through Compromised npm Package

Malicious Injective SDK Package Targets Private Keys and Seed Phrases

July 10, 2026
Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

July 8, 2026
TRON Introduces Quantum-Safe Signatures

TRON Introduces Quantum-Safe Signatures Across Nile Testnet

July 3, 2026
Taiko Bridge Reopens After $1.7 Million Hack, Restores Cross-Chain Operation

Taiko Bridge Reopens After $1.7 Million Hack, Restores Cross-Chain Operations

July 2, 2026
US Lawmakers Unveil Stop Crypto ATM Scams Act

US Lawmakers Unveil Stop Crypto ATM Scams Act After Americans Lose $333M to Fraud

June 15, 2026
US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

June 13, 2026
Next Post
Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Morgan Stanley Files ETH and SOL ETF Amendments, Unveils Market-Low Fees

Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

Kalshi Surpasses $2 Billion Revenue as IPO Discussions Begin Amid Regulatory Challenges

Recommended

  • All
  • News
TrustedVolumes Attacker Returns 1,122 ETH

TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement

July 18, 2026
Consensys Removed North Korea-Linked MetaMask Consultant After Month-Long Code Access

Consensys Hired Suspected North Korean Hacker for MetaMask Wallet: Tyler Knapp Case Revealed

July 18, 2026
FTX to Distribute $900M to Creditors in Fifth Repayment Round on July 31

FTX to Distribute $900M to Creditors in Fifth Repayment Round on July 31

July 18, 2026
France Blocks Polymarket as Global Crackdown on Prediction Markets Expands

France Blocks Polymarket as Global Crackdown on Prediction Markets Expands

July 18, 2026
SBI Holdings Acquire Coinhako

SBI Holdings Completes Majority Acquisition of Singapore Crypto Platform Coinhako

July 17, 2026
ESMA Adds 14 Crypto Firms to MiCA Register, Total Licensed CASPs Reach 294

ESMA Adds 14 Crypto Firms to MiCA Register, Total Licensed CASPs Reach 294

July 17, 2026
Argentina Traces LIBRA Funds Across Exchanges as Wallet Freeze Remains Unconfirmed

Argentina Traces LIBRA Funds Across Exchanges as Wallet Freeze Remains Unconfirmed

July 17, 2026
Bitcoin $DOG Mode Aims to Remove Bitcoin Core Relay Policy Limits

Bitcoin $DOG Mode Aims to Remove Bitcoin Core Relay Policy Limits

July 17, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Cathie Wood Buys SpaceX Dip as Stock Falls Below IPO Price
  • TrustedVolumes Attacker Returns 1,122 ETH, Retains Funds After Settlement
  • Consensys Hired Suspected North Korean Hacker for MetaMask Wallet: Tyler Knapp Case Revealed

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.