News Article · Jun 21, 2026 at 12:41 AM
2 min read 0
Member
Microsoft discovers USB worm that hijacks clipboard, steals cryptocurrency via Tor
Security #Microsoft #malware #cryptocurrency #USB worm #Tor #clipboard hijacking

Microsoft discovers USB worm that hijacks clipboard, steals cryptocurrency via Tor

Microsoft Threat Intelligence has identified a USB-propagating worm that hijacks clipboard data to steal cryptocurrency wallet addresses and seed phrases, using Tor for stealth since February 2026.

Listen to this article 3 min

Microsoft Threat Intelligence has identified a new self-propagating USB worm that monitors Windows clipboards for cryptocurrency wallet addresses and seed phrases, replacing them with attacker-controlled values and exfiltrating data through a portable Tor client. The campaign has been active since at least February 2026, according to analysis published by Microsoft this week.

The malware, tracked as Trojan:Win32/CryptoBandits.A, scans clipboard content approximately every 500 milliseconds for patterns matching Bitcoin, Tron, and Monero addresses, among others. It also captures BIP39 seed phrases, Ethereum private keys, and Bitcoin WIF keys. A successful seed phrase theft gives attackers complete control of the victim’s wallet, not just a redirected transaction.

USB propagation and layered evasion

The worm spreads through infected USB drives by hiding original documents with .doc, .xlsx, and .pdf extensions and replacing them with Windows shortcut (.lnk) files bearing the same names. When a user opens what appears to be a normal file, the .lnk executes the malware. The worm automatically copies itself to any new USB drive connected to the infected machine.

  • The initial installer is a Python executable obfuscated with PyArmor and packaged with PyInstaller.
  • JavaScript payloads dropped to C:\Users\Public\Documents use a separate dual-layer obfuscation scheme.
  • The malware checks whether Task Manager is running and exits if detected, a basic anti-analysis measure.
  • Command-and-control traffic routes through a renamed Tor client (ugate.exe) using a SOCKS5 proxy on localhost port 9050.
  • C2 endpoints include /route.php for check-ins, /recvf.php for uploading stolen files, and /stub.php for additional payloads.

Beyond clipboard theft: surveillance and remote access

The malware includes a surveillance module that captures five screenshots over a ten-second interval, giving operators a visual record of the victim’s activity. An EVAL command allows the C2 server to push and execute arbitrary code, effectively turning the cryptocurrency stealer into a general-purpose remote access tool that can adapt without reinfecting the target. Microsoft recommends disabling AutoRun and AutoPlay on Windows systems, blocking .lnk file execution from removable media via Group Policy, and restricting wscript.exe and cscript.exe through application control policies. The use of Tor for C2 communications makes traditional takedown approaches less effective because .onion addresses are not tied to registrars or hosting providers that can be compelled to act. Users should treat USB drives from unknown sources as potential vectors and ensure clipboard contents are verified before pasting cryptocurrency addresses.

Fact check

  • The malware has been active since at least February 2026.

    reported · source

  • The worm uses a renamed Tor client (ugate.exe) with a SOCKS5 proxy on localhost port 9050.

    reported · source

  • The clipboard is checked every 500 milliseconds for wallet addresses and seed phrases.

    reported · source

  • The malware targets at least six cryptocurrencies including Bitcoin (segwit, taproot), Tron, and Monero.

    reported · source

Source reporting (2)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 524 users online: 0 registered, 519 guests and 5 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Other Bot Other Crawler SemrushBot

Users active in the past 15 minutes. Total registered members: 359