Microsoft warns of new encrypted clipboard Trojan activity
U.Today
06-18 18:49
Ai Focus
Microsoft has disclosed a new encrypted clipboard trojan campaign that allows attackers to deliver malware via USB, replacing wallet addresses and mnemonic phrases.
Helpful
No.Help

Microsoft security researchers say a crypto theft campaign called "CryptoBandits" is spreading. Unlike common clipboard trojans, this type of program uses Windows' built-in scripting tools to hide its behavior, targeting encrypted wallet addresses and mnemonic phrases.

Devices can be accessed via USB.

These types of malware typically enter a victim's computer via a USB device. Once inside, it searches for common document files such as .doc, .pdf, and .xlsx, hides the original files, and then generates a malicious shortcut file with the same name.

If a user double-clicks these files as usual, they are actually triggering malware. This makes the infection process more covert and easier to bypass the user's vigilance.

Check the clipboard every half second.

Microsoft states that the Trojan installs a portable Tor client in the background, redirecting network traffic to a hidden proxy. It then checks the clipboard approximately every half second.

Once the program detects that a user has copied an encrypted wallet address or mnemonic phrase, it will replace the content with an address controlled by the attacker, causing the transferred funds to flow to the wrong target.

  • The monitored objects include wallet addresses and mnemonic phrases.
  • Clipboard checks approximately once every half second.
  • Network traffic is forwarded through a hidden proxy.

Microsoft provides protection recommendations

Microsoft warns users to be cautious about connecting USB drives from unknown sources and not to rely solely on copy-paste to complete transfers. When transferring encrypted assets, users should double-check the receiving address.

In addition, security tools need to be kept up-to-date. Microsoft specifically mentioned that Microsoft Defender should be kept up-to-date to improve its ability to detect such attacks.

Tip
$0
Like
0
Save
0
Views 177
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Microsoft warns new clipboard trojan has backdoor capabilities
Microsoft says a new encrypted clipboard trojan has backdoor capabilities that can replace wallet addresses and steal mnemonic phrases.
Cryptonews
·2026-06-18 19:20:28
920
Microsoft discovers USB worm that steals encrypted wallets
Microsoft says a Windows malware that spreads via USB monitors the clipboard, steals sensitive information from encrypted wallets, and replaces transfer addresses.
CoinDesk
·2026-06-19 17:01:46
700
Microsoft shifts to model-based routing, increasing cost pressures on enterprise AI.
Microsoft is considering introducing open-source model alternatives into its enterprise AI tools and adjusting its billing methods. The article argues that model routing and cost control are becoming core requirements for enterprise AI.
Wallstreetcn
·2026-06-18 15:06:37
385
Foreign media: Ethereum activity rose in Q1, while fees continued to decline.
According to foreign media reports, Ethereum continued to grow in users and transactions in the first quarter of 2026, on-chain fees decreased, and stablecoins and tokenized assets maintained their leading position in terms of scale.
Coinpedia
·2026-06-19 11:21:23
256
Snap splits its AI video team to form a new company, Dotmo
Snap has spun off its generative AI video team into a new company, Dotmo, which focuses on developing AI models for games and interactive entertainment.
TechCrunch
·2026-06-19 04:41:00
403