COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: CryptoBandits malware hits Windows users via USB drives since February
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > CryptoBandits malware hits Windows users via USB drives since February
Cryptocurrency NewsCryptocurrency Security

CryptoBandits malware hits Windows users via USB drives since February

In Brief

  • 🛑 CryptoBandits malware has hit Windows users since February via USB drives.

  • ⚡ The malware steals crypto wallet data and changes clipboard addresses to steal funds in $BTC.

  • 🖱️ Victims unknowingly spread the virus by plugging infected USB drives into new computers.

Ömer Ergin
Ömer Ergin 2 hours ago
Share
SHARE

Microsoft has identified a new strain of malware targeting the cryptocurrency wallets of Windows users, spreading through USB drives since February. The company refers to this threat as a “crypto clipper” and tracks it under the name Trojan:Win32/CryptoBandits in Microsoft Defender Antivirus.

Contents
How does the malware operate?What data is targeted?USB-based propagation methodMicrosoft’s security recommendations

How does the malware operate?

The attack begins with a malicious shortcut file (.lnk extension) placed on an infected USB drive. Although these files are typically used to open programs or folders in Windows, clicking on the compromised shortcut installs a worm-like malware onto the device.

After installation, the malware simultaneously carries out two key tasks. First, it perpetually runs its primary code to gather information from crypto wallets. Second, it continuously waits for a clean USB device to be connected to the same computer, enabling the infection to propagate across multiple portable devices and systems.

According to Microsoft, the malware regularly monitors clipboard data, collecting information such as seed phrases, private keys, and recipient addresses. This data is then sent to attackers via the Tor network. Additionally, when a user copies a wallet address for a transaction, the malware can covertly replace it with an address controlled by the attacker, making unauthorized transfers possible.

What data is targeted?

Microsoft notes that the malware scans the Windows clipboard roughly every 500 milliseconds. If a user copies a seed phrase or private key from a wallet such as Bitcoin or Ethereum, the software captures these sensitive details. The malware also takes up to five screenshots at ten-second intervals and transmits them externally.

One of the most critical risks is the silent replacement of transfer addresses. When users copy a recipient address to send funds, the malware can swap it out for an attacker’s address just before it is pasted—without any visible warning—potentially diverting cryptocurrency to unauthorized hands.

Mini glossary: The Tor network is an open-source platform that enhances privacy by routing internet traffic through various servers. It is often used in cyberattacks to conceal command-and-control communication.

USB-based propagation method

The method of spreading via USB stands out as another notable feature. When a clean USB drive is connected to a compromised computer, the malware scans it for files like Word, Excel, and PDF documents. It then replaces these with similarly named shortcut files, thereby infecting the USB drive as well.

This tactic can mislead users into thinking their files are unchanged, allowing the infection cycle to continue as the compromised USB drive is connected to other devices, facilitating broader spread.

Microsoft’s security recommendations

Microsoft recommends disabling the AutoRun feature for removable media, blocking the execution of .lnk files on USB drives via group policies, and restricting script hosts such as wscript.exe and cscript.exe. The company also urges IT teams to scan their networks for indicators of compromise that have been published.

Indicators include file hashes and .onion domain addresses reportedly linked to command-and-control servers. Customers with Microsoft Defender are further advised to check for suspicious connections to the local Tor proxy on port 9050 and review related activities within their systems.

You can follow our news on X, Telegram, Facebook & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

STRC plunges to $82.50 as digital credit market reels

Sec seeks market input on swap reporting rules in June 2024

XRP drops 3.4 percent as key $1.15 support fails

BTC now trades 20 percent below mining cost at $62,500

Investors flock to BTC put options as prices dip to $62,400

Ömer Ergin 19 June, 2026 - 2:03 pm 19 June, 2026 - 1:53 pm
Share This Article
Facebook Twitter
Share
Previous Article Ethereum core teams could face funding shortfall within 9 months
Next Article Sec seeks market input on swap reporting rules in June 2024
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Daily XRP transfer volume surpasses 500 million! What does this mean during the latest price drop?
Ripple (XRP)
Major XRP wallets now control 93 percent of the supply! What are analysts signaling for the next move?
Ripple (XRP)
Algorand unveils 2027 roadmap to protect network from quantum threats
Blockchain News
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?