TLDR Microsoft identified new USB-based malware targeting crypto wallets on Windows systems. The malware, tracked as Trojan:Win32/CryptoBandits, spreads throughTLDR Microsoft identified new USB-based malware targeting crypto wallets on Windows systems. The malware, tracked as Trojan:Win32/CryptoBandits, spreads through

Microsoft Finds USB Worm Hijacking Crypto Wallet Transfers

2026/06/19 17:14
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

TLDR

  • Microsoft identified new USB-based malware targeting crypto wallets on Windows systems.
  • The malware, tracked as Trojan:Win32/CryptoBandits, spreads through infected “.lnk” shortcut files.
  • Once executed, it installs a worm that runs continuously on the infected device.
  • The worm monitors clipboard activity every 500 milliseconds to capture sensitive crypto data.
  • It steals seed phrases and private keys for Bitcoin and Ethereum wallets.

Microsoft has identified new malware that spreads through USB drives and targets crypto wallet data on Windows systems. The threat uses shortcut files to install a worm that steals sensitive information. The company confirmed the malware captures wallet keys and redirects transactions without user awareness.

Microsoft Tracks USB Worm Targeting Crypto Wallets

Microsoft reported that the malware operates as a crypto clipper and spreads through infected USB drives. It uses malicious shortcut files with “.lnk” extensions to execute hidden commands when opened. Once triggered, the malware installs a worm that runs continuously on the infected system.

The worm performs two parallel actions after installation on Windows devices. It executes wallet-stealing code while preparing to infect other USB drives connected later. Microsoft identified the malware as Trojan/CryptoBandits through its Defender Antivirus system.

The infection begins when a user clicks a disguised shortcut file on a USB drive. The system then loads hidden scripts that install the worm silently. As a result, the malware remains active without showing visible warnings.

Malware Captures Wallet Keys and Alters Transactions

The malware monitors clipboard activity every 500 milliseconds to capture sensitive crypto data. It detects copied seed phrases or private keys linked to Bitcoin or Ethereum wallets. Once captured, the malware sends the data to attacker-controlled servers through the Tor network.

The worm also captures screenshots at ten-second intervals to gather further information. It sends five images along with clipboard data to remote servers. This process allows attackers to track user actions and extract wallet details.

The threat extends beyond data theft by altering transaction behavior. When users copy wallet addresses, the malware replaces them with attacker-controlled addresses. As a result, funds get redirected without the user noticing any visible change.

Worm Spreads Through USB Drives Using File Replacement

The malware spreads by infecting clean USB drives connected to an already compromised system. It scans for common files such as Word documents, Excel sheets, and PDFs. Then it replaces them with malicious shortcut files using identical names.

These infected drives continue the cycle when connected to other computers. Users who open the replaced files unknowingly trigger the malware again. This propagation method allows the worm to expand across multiple systems quickly.

Microsoft advised disabling AutoRun features for removable media to reduce infection risks. It also recommended blocking the execution of .lnk files from USB drives through group policy settings. The company further urged restricting script hosts like wscript.exe and cscript.exe to limit execution paths.

Security teams can monitor systems using Defender tools and hunting queries. Microsoft also released indicators of compromise, including file hashes and .onion domains. These details help organizations detect and respond to the malware activity.

The post Microsoft Finds USB Worm Hijacking Crypto Wallet Transfers appeared first on Blockonomi.

Market Opportunity
Based Logo
Based Price(BASED)
$0.09357
$0.09357$0.09357
-0.34%
USD
Based (BASED) Live Price Chart

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel