Microsoft reveals a new type of cryptocurrency-stealing Trojan called Crypto Clipper, which has infected multiple Windows devices since February of this year
The Microsoft Security Blog reported that the Microsoft security research team discovered a new type of cryptocurrency stealing Trojan named Crypto Clipper. This malware has been active since February 2026, primarily spreading through USB devices that infect Windows users with malicious .lnk shortcuts. Crypto Clipper has a built-in Tor client that connects to .onion hidden services via a local SOCKS5 proxy, enabling covert C2 communication. Its main functions include high-frequency monitoring of the clipboard, stealing mnemonic phrases and private keys, replacing cryptocurrency transfer addresses, capturing screenshots and uploading them, as well as receiving remote code execution commands.
Microsoft stated that this malware has worm propagation capabilities, automatically hiding original documents on USB drives and generating malicious shortcuts with the same name, while also creating scheduled tasks for persistent control. Researchers detected it as Trojan:Win32/CryptoBandits.A and recommended that users disable autorun for removable devices, restrict script interpreter execution permissions, and closely monitor localhost:9050 Tor proxy traffic and abnormal clipboard access behaviors.
You may also like

WEEX All-New Search Features: Find, Trade & Earn Faster Than Ever

Will MicroStrategy fall into a death spiral? What will the macro trend be in the second half of the year?

Morning Report | Illinois signs the strictest digital asset tax law in the U.S.; RWA tokenization market size surpasses $43 billion, institutions accelerate the migration of on-chain assets

Full version of the debut Q&A! Federal Reserve Chairman Waller: Sticking to the 2% inflation target, establishing five special working groups, individual did not submit the dot plot

From Disruptor to Shadow Market: The Crypto Market is Becoming a Colony of Traditional Finance

Dalio's important long article: How to position in the current market environment?

OKX Star analyzes Binance's competitive advantages: when regulation levels the playing field, competition has just begun

New gameplay for participating in initial offerings on cryptocurrency exchanges

Why Is Bitcoin Down Today? What the Hawkish FOMC Means for SpaceX, Gold and Nasdaq

DeepSeek Financing Story

Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin

Cursor, why did you get on Musk's spaceship?

In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?

Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?




