The Microsoft Safety Weblog reported that the Microsoft safety analysis crew found a new type of cryptocurrency stealing Trojan named Crypto Clipper. This malware has been energetic since February 2026, primarily spreading by means of USB devices that infect Windows customers with malicious .lnk shortcuts. Crypto Clipper has a built-in Tor consumer that connects to .onion hidden companies through a native SOCKS5 proxy, enabling covert C2 communication. Its essential features embody high-frequency monitoring of the clipboard, stealing mnemonic phrases and personal keys, changing cryptocurrency switch addresses, capturing screenshots and importing them, in addition to receiving distant code execution instructions.
Microsoft acknowledged that this malware has worm propagation capabilities, mechanically hiding authentic paperwork on USB drives and producing malicious shortcuts with the identical title, whereas additionally creating scheduled duties for persistent management. Researchers detected it as Trojan:Win32/CryptoBandits.A and advisable that customers disable autorun for detachable devices, limit script interpreter execution permissions, and carefully monitor localhost:9050 Tor proxy site visitors and irregular clipboard entry behaviors.









