Microsoft security researchers have uncovered a crypto-stealing malware campaign active since February 2026.
Tracked as Trojan:Win32/CryptoBandits.A, this software spreads through USB drives, monitors clipboards every 500 milliseconds, and swaps copied wallet addresses with attacker destinations. This campaign represents a strategic evolution toward offline physical vectors to breach digital asset security.
🚨MICROSOFT WARNS OF NEW CRYPTO-STEALING MALWARE!!!
Active since February, the malware swaps copied wallet addresses with the attacker’s, steals seed phrases, and stays hidden via Tor.
Spreading through infected USB drives.
Always stay vigilant. pic.twitter.com/ho0aCdAY3H
— Crypto Banter (@crypto_banter) June 19, 2026
How does the clipper worm hijack your crypto transactions?
The infection begins when an unsuspecting user inserts an infected USB drive into a computer. The malware uses hidden shortcut files to launch a malicious worm component that automatically copies itself across local storage devices. Once inside a Windows system, it remains hidden by using bundled Tor proxies to mask communications with command servers.
The crisis occurs mid-transaction during everyday operations. As an investor copies a destination address, the software intercepts the clipboard data within half a second. It swaps the text with the hacker’s wallet address. Unwary users who omit manual verification send funds directly to the thieves. The program also scans local files to exfiltrate private keys and seed phrases.
To stop this fast-spreading worm, investors must immediately adjust their daily habits. Disable AutoRun features on Windows machines and reject unfamiliar USB devices. Most importantly, verify every alphanumeric character of a wallet address before confirming a transfer. Using air-gapped hardware wallets remains the most reliable protection to keep seed phrases safe.
How has Microsoft been combating crypto malware
Microsoft previously warned of malware hidden in two npm packages (utils-terminal@3.2.1, logger-active@3.2.1) that steals crypto wallet credentials via a remote access trojan, capturing keystrokes and screenshots while exfiltrating data through Hugging Face.
In May 2025, Microsoft led a globally coordinated takedown dismantling the Lumma Stealer cybercrime operation, the world’s largest infostealer malware active since late 2022.
Acting on a U.S. federal court order, Microsoft’s Digital Crimes Unit seized 2,300 malicious domains forming Lumma’s command-and-control backbone, while the DOJ disrupted its central control panel and dark web marketplaces. Europol’s EC3 and Japan’s JC3 suspended residual servers in Europe and Asia.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads and CoinMarketCap Community for seamless access to high-quality industry insights.
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

























































































