Open account

USB-Borne Crypto Clipper Malware Targets Bitcoin and Ethereum Wallets on Windows

Microsoft warns of a USB-borne Windows malware campaign, tracked as Trojan:Win32/CryptoBandits, that has been active since February 2026 and specifically targets Bitcoin and Ethereum wallet users. The malware spreads through compromised removable drives using malicious .lnk shortcuts, then scans the clipboard about every 500 milliseconds to steal seed phrases and private keys. It also replaces copied wallet addresses with attacker-controlled addresses, enabling transaction redirection. The threat exfiltrates data via Tor and captures screenshots to support further theft. The article is primarily a cybersecurity warning rather than a market-moving crypto price story, but it highlights elevated operational risk for crypto holders and exchanges. Microsoft recommends disabling AutoRun, blocking .lnk execution from USB devices, and restricting script host tools to reduce exposure.

Category

Bitcoin

Sentiment

Bearish

Event

Security incident

Reading time

1 min