返回新闻列表
Cointelegraph2026/06/19 05:33作者未公开

Microsoft Flags USB Crypto Clipper Hijacking Wallets

Microsoft Flags USB Crypto Clipper Hijacking Wallets
单篇新闻分析中性影响 81

AI 摘要

The malware blends data theft with remote code execution, “turning a financially motivated stealer into a lightweight backdoor,” Microsoft said. Microsoft Threat Intelligence is warning Windows users about a cryptocur...

利好评分
12
利空评分
12
风险等级
btcethtrx安全

风险提示

这条新闻可能带来较大波动,建议先核对原文和后续公告。

所属事件

同一市场事件下的相关新闻会集中整理,方便回到来源核对。

1 个事件
安全事件中性影响 811 个来源

Microsoft Flags USB Crypto Clipper Hijacking Wallets

The malware blends data theft with remote code execution, “turning a financially motivated stealer into a lightweight backdoor,” Microsoft said. Microsoft Threat Intelligence is warning Windows users about a cryptocur...

风险 最近更新 2026/06/19 08:04btcethtrx查看事件

The malware blends data theft with remote code execution, “turning a financially motivated stealer into a lightweight backdoor,” Microsoft said.

Microsoft Threat Intelligence is warning Windows users about a cryptocurrency clipper strain of malware transmitted via USB drives.

The malware, which has been affecting users since February, steals clipboard data to extract wallet credentials using “high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution,” Microsoft said Wednesday.

The crypto clipper also hides legitimate files and replaces them with lookalike shortcuts, so victims unknowingly execute malware while a worm component propagates automatically to USB storage devices.

This malware is insidious because it's more than just an info stealer, it functions as a backdoor, meaning that attackers can push and execute arbitrary code on infected machines at any time, turning a simple crypto theft into a persistent foothold for ransomware.

The execution of this clipper is also notable because it does not depend on a traditional installer or exposed IP-based infrastructure, the Microsoft researchers said.

The malware deploys two obfuscated JavaScript payloads in the Windows Documents directory and creates scheduled tasks for both the worm and stealer components.

The malware also secretly installs a copy of Tor on the victim’s computer but renames it ugate.exe to disguise it as something innocent. It then uses the anonymizing Tor network to connect to its malicious operators at hidden “onion” addresses.

Related: ‘TrapDoor’ malware targets crypto dev tools in supply chain attack

“The combination of Tor-routed C2, clipboard targeting, screenshot capture and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices,” Microsoft said.

Crypto clipper execution flow. Source: Microsoft

The crypto clipper focuses on “high-value financial artifacts” from the clipboard, including BIP39 mnemonic seed phrases and Bitcoin and Ethereum private keys.

It also replaces copied wallet addresses with attacker-controlled ones across Bitcoin, Tron and Monero and takes screenshots every ten seconds for additional context.

Microsoft Defender Antivirus detects the malware as Trojan:Win32/CryptoBandits.A .

Microsoft recommended disabling autoplay on removable media, blocking .lnk execution from USB drives, and monitoring for proxy activity and spawned scripts.

2026 has seen a significant escalation in Windows-based crypto stealers. A new Windows malware strain called Lucid Stealer that targets browser extensions and crypto wallets was identified earlier this month by the Foresiet Threat Intel Team.

Magazine: The end of anon? AI could unmask crypto’s hidden identities

Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.

All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy .

新闻图片

Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 2
Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 3
Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 4
Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 5
Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 6
Microsoft Flags USB Crypto Clipper Hijacking Wallets 图片 7
Microsoft Flags USB Crypto Clipper Hijacking Wallets | 币小二