No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Microsoft Flags USB Crypto Clipper Hijacking Wallets

June 20, 2026
in Crypto
0
Cointelegraph


Microsoft Threat Intelligence is warning Windows users about a cryptocurrency clipper strain of malware transmitted via USB drives. 

The malware, which has been affecting users since February, steals clipboard data to extract wallet credentials using “high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution,” Microsoft said Wednesday.

The crypto clipper also hides legitimate files and replaces them with lookalike shortcuts, so victims unknowingly execute malware while a worm component propagates automatically to USB storage devices. 

This malware is insidious because it’s more than just an info stealer, it functions as a backdoor, meaning that attackers can push and execute arbitrary code on infected machines at any time, turning a simple crypto theft into a persistent foothold for ransomware. 

The execution of this clipper is also notable because it does not depend on a traditional installer or exposed IP-based infrastructure, the Microsoft researchers said.

“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking.”  

Tor network used for obfuscation 

The malware deploys two obfuscated JavaScript payloads in the Windows Documents directory and creates scheduled tasks for both the worm and stealer components.

The malware also secretly installs a copy of Tor on the victim’s computer but renames it ugate.exe to disguise it as something innocent. It then uses the anonymizing Tor network to connect to its malicious operators at hidden “onion” addresses.

Related: ‘TrapDoor’ malware targets crypto dev tools in supply chain attack

“The combination of Tor-routed C2, clipboard targeting, screenshot capture and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices,” Microsoft said. 

Crypto clipper execution flow. Source: Microsoft

Private keys and seed phrases targeted 

The crypto clipper focuses on “high-value financial artifacts” from the clipboard, including BIP39 mnemonic seed phrases and Bitcoin and Ethereum private keys. 

It also replaces copied wallet addresses with attacker-controlled ones across Bitcoin, Tron and Monero and takes screenshots every ten seconds for additional context. 

Microsoft Defender Antivirus detects the malware as Trojan:Win32/CryptoBandits.A.

Microsoft recommended disabling autoplay on removable media, blocking .lnk execution from USB drives, and monitoring for proxy activity and spawned scripts. 

2026 has seen a significant escalation in Windows-based crypto stealers. A new Windows malware strain called Lucid Stealer that targets browser extensions and crypto wallets was identified earlier this month by the Foresiet Threat Intel Team. 

Magazine: The end of anon? AI could unmask crypto’s hidden identities

Editorial Team

Editorial Team

Related Posts

Andre Cronje leaves Sonic board as token slump sparks overhaul - 1
Crypto

Andre Cronje leaves Sonic board as token slump sparks overhaul

June 20, 2026
Bitcoin
Crypto

Bitcoin Must Hold $60K Or Risk Major Breakdown, TradingView

June 20, 2026
Cointelegraph
Crypto

Franklin Files Passive ETFs that Reinvest Dividends into Bitcoin Exposure

June 20, 2026
Bitcoin erases CPI gains after Trump escalates Iran threats - 1
Crypto

Why is Bitcoin price going up today?

June 20, 2026
Venus
Crypto

Venus Protocol Integrates Tokenized Stocks As Lending Collat

June 20, 2026
Cointelegraph
Crypto

Bitcoin Rotations Into Altcoin Market is Collapsing: Is Altseason Postponed?

June 20, 2026
Load More

Popular News

  • Micron, Intel drag the tech sector into a new bearish phase. Will the correction last this time?

    Micron, Intel drag the tech sector into a new bearish phase. Will the correction last this time?

    0 shares
    Share 0 Tweet 0
  • 10 Signs an Airdrop Is a Scam — and How to Stay Safe

    0 shares
    Share 0 Tweet 0
  • Where to get high yield on stablecoins in 2025: Top 5 projects

    0 shares
    Share 0 Tweet 0
  • How Oura, Whoop, Garmin, Apple Watch, and Fitbit Calculate Sleep Scores

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0

Latest News

Cointelegraph

Microsoft Flags USB Crypto Clipper Hijacking Wallets

June 20, 2026
0

Microsoft Threat Intelligence is warning Windows users about a cryptocurrency clipper strain of malware transmitted via USB drives. The malware, which...

Andre Cronje leaves Sonic board as token slump sparks overhaul - 1

Andre Cronje leaves Sonic board as token slump sparks overhaul

June 20, 2026
0

Sonic Labs has announced a leadership overhaul after the S token extended its long-running decline, with former chief technology officer...

Report says UK PM Starmer ready to quit, but source says he is still focused on the job

Report says UK PM Starmer ready to quit, but source says he is still focused on the job

June 20, 2026
0

Report says UK PM Starmer ready to quit, but source says he is still focused on the job

Bitcoin

Bitcoin Must Hold $60K Or Risk Major Breakdown, TradingView

June 20, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR Weslad says Bitcoin is testing...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.