Back Kucoin Microsoft Discovers Crypto Clipper Malware Targeting Windows Devices Since February 2026
ChainCatcher reports that Microsoft Security Blog announced the discovery of a new cryptocurrency-stealing Trojan named Crypto Clipper by Microsoft’s security research team. Active since February 2026, this malware primarily infects Windows users via malicious .lnk shortcut files distributed through USB devices. Crypto Clipper includes a built-in Tor client that connects to .onion hidden services through a local SOCKS5 proxy to enable covert C2 communication. Its core functionalities include high-frequency clipboard monitoring, theft of mnemonic phrases and private keys, replacement of cryptocurrency transfer addresses, screenshot capture and upload, and execution of remote code commands. Microsoft states that the malware possesses worm-like propagation capabilities: it automatically hides original documents on USB drives and generates malicious shortcuts with identical names, while creating scheduled tasks to maintain persistence. Researchers have detected it as Trojan:Win32/CryptoBandits.A and recommend users disable auto-run for removable devices, restrict script interpreter execution permissions, and closely monitor traffic on localhost:9050 (Tor proxy) and unusual clipboard access patterns.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
