New Crypto Clipper Malware Uses USB and Tor for Stealthy Attacks

New Crypto Clipper Malware Uses USB and Tor for Stealthy Attacks

First seen 18 Jun 2026, 11:41 UTC Blogs.MicrosoftFeeds.4SysopsThehackernewsCoineditionBleepingcomputer+18 88% similarity 69.0

Article Content

Browse articles
ThreatCluster

Microsoft has identified a new cryptocurrency-stealing malware named Crypto Clipper, active since February 2026. This malware spreads primarily through malicious Windows shortcut files (.lnk) on USB drives, targeting Windows users. It employs worm-like behavior, enabling it to propagate itself to other USB devices. The malware monitors clipboard contents for cryptocurrency wallet addresses and can replace them with those controlled by the attacker. Additionally, it captures sensitive information such as seed phrases and private keys, and it can take screenshots of the victim's screen. Communication with its command-and-control server is conducted over the Tor network, making detection difficult. Microsoft recommends focusing on behavioral detection rather than relying solely on traditional signature-based methods. Security teams are advised to monitor for unusual script activity and connections to localhost:9050, which indicates Tor usage. The malware has been classified as Trojan:Win32/CryptoBandits.A.

Key Points: • Crypto Clipper malware spreads via USB drives using malicious .lnk files. • It monitors clipboard data for cryptocurrency addresses and steals sensitive information. • The malware uses Tor for covert communication, complicating detection efforts.

ThreatCluster AI How this analysis works

Timeline

2026-02-01
Crypto Clipper malware campaign begins
The Crypto Clipper malware campaign has been active since February 2026, targeting cryptocurrency wallets.
Coinedition
2026-06-17
Microsoft publishes detailed analysis
Microsoft Threat Intelligence released a report detailing the capabilities and attack methods of Crypto Clipper.
Blogs.Microsoft
2026-06-18
Multiple outlets report on Crypto Clipper
Cybersecurity news outlets report on the malware's capabilities, including clipboard monitoring and Tor communication.
Bleepingcomputer
2026-06-19
Microsoft issues recommendations for defense
Microsoft advises security teams to monitor for behavioral indicators and restrict script execution permissions to combat Crypto Clipper.
Kucoin

Community

Browse all →