Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
    The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Microsoft Uncovers Tor-Powered ‘CryptoBandits’ Malware Emptying User Wallets

The sophisticated campaign uses built-in Windows scripts to capture screenshots and manipulate copy-paste data, forcing a shift toward behavioral security monitoring over traditional antivirus flags.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: 1 hour ago
Published 1 hour ago
Share
Microsoft Uncovers Tor-Powered 'CryptoBandits' Malware Emptying User Wallets
Show AI Summary
Malware campaign targeting Windows users began in February 2026, using infected USB drives and malicious files.
Attackers use Tor network to control compromised devices, allowing them to steal wallet data and replace crypto addresses.
Microsoft urges security teams to monitor suspicious behavior, as malware can operate undetected using built-in Windows tools.

Microsoft has uncovered a sophisticated, cryptocurrency-stealing malware campaign that has been actively targeting Windows users since February 2026. Distributed through infected USB drives and malicious shortcut files, the malware allows attackers to steal wallet data, take screenshots, and replace copied crypto wallet addresses with their own.

According to Microsoft threat intelligence researchers, the operation relies on the Tor network to obfuscate its communications and maintain persistent control over compromised devices. By blending clipboard theft, wallet address replacement, and worm-like propagation, the malware is exceptionally difficult to detect. Microsoft has urged security teams to focus on suspicious behavior rather than relying solely on known indicators of compromise.

Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…

— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026

Malware turns devices into crypto traps

In a blog post, Microsoft said the malware, tracked by Defender Antivirus as CryptoBandits, uses built-in Windows tools like Windows Script to operate in the background. It routes its command-and-control communications through the Tor network to help conceal its activity. Once installed, it continuously monitors a user’s clipboard for sensitive crypto-related information, including wallet addresses, private keys and recovery phrases.

The malware can also capture screenshots and send stolen data to attackers through Tor. In addition, it can receive remote commands, giving hackers ongoing access to infected devices.

According to Microsoft, the attack often begins with malicious shortcut files distributed through infected USB drives. These files can hide legitimate documents and replace them with fake shortcuts carrying the same names, increasing the chances that users will unknowingly trigger the malware.

Endpoint attacks continue to evolve

Microsoft advised security teams to watch for unusual script activity, unexpected clipboard changes and traffic linked to the Tor network, which the malware uses to communicate with attackers. The company also urged users to pay attention to unexplained screen-capture activity and other signs that a device may have been compromised.

The warning comes as cybercriminals target users’ devices rather than blockchain networks themselves. Laptops, web browsers and software development environments have become attractive entry points for attackers seeking access to digital assets.

Recent malware campaigns have followed a similar playbook. TrapDoor targeted cryptocurrency and AI developers, while StilachiRAT focused on browser-based wallets and clipboard monitoring. SparkCat, meanwhile, searched screenshots for crypto recovery phrases. Binance has also warned users about clipper malware that replaces copied wallet addresses with those controlled by attackers.

Users must verify their wallets before initiating transactions and refrain from using any unfamiliar USB device while making sure their security software is up-to-date. As per Microsoft, “suspicious activity monitoring” is considered one of the best ways to identify such threats before incurring any monetary damage.

Also Read: Ireland Targets Crypto Risks in New 30-Point Crime Action Plan

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackMicrosoft
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Sr. Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
SEC and CFTC Launch Historic Joint Review of Crypto Derivatives Rules
Morgan Stanley Files for Spot Ethereum ETF With Staking
Morgan Stanley Files for Spot Ethereum ETF With Staking
Why is Bitcoin and Crypto Market Down Today?
Why is Bitcoin and Crypto Market Down Today?
Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum
Kalshi Surpasses $2 Billion Revenue as IPO Talks Gain Momentum
The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?

Find Us on Socials

You may also like

Aztec Network’s RollupProcessor Exploited for $2.21 Million

Aztec Network’s RollupProcessor Exploited for $2.21 Million 

Little Boy Plus Loses $377K After Exploit Targets Minting Bug

Little Boy Plus Loses $377K as “No-Admin-Key” DeFi Protocol Gets Drained via Mint Bug

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

DeFi Tokens Are Shifting From Hype to Hard Numbers Grayscale

DeFi Tokens Are Shifting From Hype to Hard Numbers: Grayscale

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information