Key Takeaways
- Microsoft flagged a Windows crypto clipper malware active since February 2026.
- It spreads through malicious shortcut files on USB drives.
- The malware steals seed phrases and swaps copied wallet addresses.
- It hides its command server inside the Tor network.
- Microsoft Defender detects it as Trojan:Win32/CryptoBandits.A.
- It attacks the device, not the blockchain or the exchange.
- Attacks on individual wallets are a fast-growing share of crypto theft.
Microsoft has uncovered a crypto-stealing malware campaign that skips the blockchain entirely and goes straight for the user’s devi...


English (US)