No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Microsoft warns crypto clipper now acts like backdoor

June 18, 2026
in Crypto
0
Microsoft warns crypto clipper now acts like backdoor



Microsoft Threat Intelligence has warned of a Windows-based crypto clipper campaign that has affected users since February 2026.

Summary

  • Microsoft says CryptoBandits uses Tor-routed communication, wallet replacement, screenshots, and remote code execution on Windows.
  • The malware spreads through malicious shortcut files and creates more infected shortcuts from legitimate files.
  • Security teams should hunt linked behaviors, not isolated alerts, to catch this attack chain early.

In a Microsoft blog, researchers said the malware steals clipboard data, replaces wallet addresses, and searches for valuable crypto information.

The company said Microsoft Defender Antivirus detects the threat as Trojan:Win32/CryptoBandits.A. In an X post, Microsoft said the campaign combines clipboard theft, wallet address replacement, worm-like behavior, and Tor-based communication.

Malware spreads through shortcut files

Microsoft said the attack starts with malicious .lnk shortcut files. These files can arrive through USB storage devices and launch a worm component on infected Windows systems. Once active, the malware creates more malicious shortcuts from legitimate files found on the device.

Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…

— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026

The worm also sets up scheduled tasks for persistence. This allows the malware to keep running after restart and gives attackers a longer window to monitor the device. Microsoft said the threat uses script-based tools rather than a large installer, making simple file-based detection harder.

Tor hides command traffic

The clipper deploys a portable Tor client and routes traffic through a local SOCKS5 proxy. Microsoft said the malware uses localhost:9050 and .onion command-and-control domains to reduce normal DNS visibility and make blocking harder.

The malware checks the clipboard about every 500 milliseconds. It looks for seed phrases, private keys, and crypto wallet addresses. If it finds a wallet address, it can replace it with an attacker-controlled address. If it finds a seed phrase or private key, it can send the data through Tor.

Backdoor features raise risk

Microsoft said the campaign goes beyond basic wallet address switching. The malware can upload screenshots, contact a hidden command server, and run attacker-supplied code through an EVAL command. That turns a crypto stealer into a lightweight backdoor.

The company said, “defenders should hunt for correlated behaviors rather than investigate isolated events.” It advised teams to watch for script engines launching curl, cmd.exe, PowerShell, or unexpected files, especially when paired with localhost:9050 traffic.

Crypto users remain frequent targets

As crypto.news reported earlier, StilachiRAT also targeted crypto wallets and monitored clipboard activity. That Microsoft-linked warning covered malware that could scan browser wallets and extract stored data.

According to an earlier crypto.news report, SparkCat malware used image scanning to search for wallet seed phrases in screenshots. crypto.news previously reported that Binance warned about clipper malware that replaced copied wallet addresses with attacker-controlled ones.

The new Microsoft report shows that clipper malware is becoming more layered. It no longer only waits for users to copy a wallet address. It can spread, hide traffic through Tor, steal wallet data, capture screens, and keep access to the system.

Editorial Team

Editorial Team

Related Posts

G7 calls for joint action on North Korean crypto theft, cybercrime
Crypto

G7 calls for joint action on North Korean crypto theft, cybercrime

June 18, 2026
CLARITY Act Fast-Track Hinges on Senate Floor Vote Before Recess
Crypto

CLARITY Act Fast-Track Hinges on Senate Floor Vote Before Recess

June 18, 2026
Grayscale Applies Cash-Flow Valuation Model To AAVE In New
Crypto

Grayscale Applies Cash-Flow Valuation Model To AAVE In New

June 18, 2026
Cointelegraph
Crypto

Block’s Builderbot AI Handles 15% of Production Code

June 18, 2026
BitGo hires ex-MAS regulator to power APAC crypto push
Crypto

BitGo hires ex-MAS regulator to power APAC crypto push

June 18, 2026
SEC
Crypto

Hayden Adams Comments On US Securities Laws Following SEC Overreach Concerns

June 18, 2026
Load More
Next Post
Gasoline prices just fell below $4 per gallon — by the smallest possible amount

Gasoline prices just fell below $4 per gallon — by the smallest possible amount

Popular News

  • The 10 best banks for college students in 2025

    The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • NYC Subway Disables Trip-History Feature Over Tap-and-Go Privacy Concerns

    0 shares
    Share 0 Tweet 0
  • Where to get high yield on stablecoins in 2025: Top 5 projects

    0 shares
    Share 0 Tweet 0
  • Tiananmen vigils shift overseas as Hong Kong falls silent By Reuters

    0 shares
    Share 0 Tweet 0

Latest News

Stocks making the biggest moves premarket: INTC, SPCX, MU, CCL

Stocks making the biggest moves premarket: INTC, SPCX, MU, CCL

June 18, 2026
0

Check out the companies making the biggest moves in premarket trading: Intel — The semiconductor company soared nearly 9% after...

G7 calls for joint action on North Korean crypto theft, cybercrime

G7 calls for joint action on North Korean crypto theft, cybercrime

June 18, 2026
0

G7 leaders broadened their warning over North Korean crypto theft to include wider cybercrime as researchers link DPRK-affiliated actors to...

Investors signal appetite for private credit in emerging markets

Moody’s: European banks’ private credit exposure remains limited

June 18, 2026
0

European banks have extended around €120bn (£104bn) in loans to private credit funds, equivalent to only around 0.7 per cent...

Check Out These Early Prime Day Deals on Travel Essentials Before Your Next Trip

Check Out These Early Prime Day Deals on Travel Essentials Before Your Next Trip

June 18, 2026
0

Amazon Prime Day is almost here, and I have a cart full of wish-listed items I'm hoping to save on....

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.