Microsoft Warns About CryptoBandits
Microsoft has uncovered CryptoBandits malware that steals cryptocurrency by replacing wallet addresses.
Microsoft cybersecurity researchers have identified a new and sophisticated campaign targeting cryptocurrency users. The threat has been dubbed CryptoBandits.
The attack relies on a type of malware known as a clipper. For years, clippers have been used to replace copied cryptocurrency wallet addresses with addresses controlled by cybercriminals. However, CryptoBandits introduces a far more advanced version of this technique.
The malware spreads through infected USB drives while disguising itself as ordinary documents. Once executed on a computer, it searches for commonly used file types such as .doc, .pdf, and .xlsx files, hides the originals, and replaces them with malicious .lnk shortcut files bearing the same names. Clicking one of these shortcuts silently triggers the infection without the user's knowledge.
The malware then installs a portable Tor client, routing internet traffic through a hidden proxy server. It continuously monitors the system clipboard every half second, looking for cryptocurrency wallet addresses and recovery phrases. When such data is detected, it is automatically replaced with information controlled by the attackers.
According to Microsoft, the campaign is particularly dangerous because it avoids using large installation files that antivirus software can easily detect. Instead, it relies on scripting tools already built into Windows, making the threat much harder to identify during routine security scans.
Security experts advise users to exercise caution when connecting unknown USB devices. They also recommend verifying wallet addresses before sending any funds and avoiding reliance solely on clipboard data. Microsoft further stresses the importance of keeping security tools up to date, including Microsoft Defender.