Microsoft reveals new encrypted Trojan capable of stealing mnemonic phrases
AMBCrypto
1h ago
Ai Focus
Microsoft has discovered a new cryptographic trojan, Crypto Clipper, which can steal mnemonic phrases, replace transfer addresses, and maintain remote control via Tor.
Helpful
No.Help

Microsoft security researchers have discovered an expanding malware campaign specifically targeting encrypted users. This type of trojan, named Crypto Clipper, is said by Microsoft to date back to February 2026. Unlike common clipboard hijackers, this version also possesses the ability to steal sensitive information, take screenshots, and remotely execute code.

It can steal mnemonic phrases and private keys.

According to Microsoft, Crypto Clipper continuously monitors the clipboard of victims' devices, searching for high-value encrypted data. Targets include 12-word and 24-word mnemonic phrases, Ethereum private keys, and Bitcoin wallet credentials.

Once relevant content is identified, the Trojan transmits the data through a Tor-based command and control infrastructure. It also captures device screens, helping attackers to obtain more information such as wallet interfaces and account balances.

Replaceable transfer address

Another key capability of this attack is its ability to replace the user's copied wallet address. Microsoft stated that the Trojan checks the address in the clipboard and changes it to a similar address controlled by the attacker, reducing the likelihood that the user will notice anything amiss when making a transfer.

  • It has been confirmed that the Bitcoin network is involved.
  • At the same time, for Tron addresses
  • It also covers Monero.

This means that if a user does not carefully verify the receiving address, their assets could be transferred to an attacker's wallet.

Maintaining long-term control through Tor

Microsoft also noted the concerning method of propagation used in this campaign. Researchers discovered that the Trojan deployed a portable Tor client and communicated with attackers through a hidden service.

Building on this, attackers can not only steal clipboard content but also issue further instructions to infected devices, including executing arbitrary code. Microsoft believes that the combination of clipboard theft, screenshots, Tor communication, and remote task control allows attackers to quickly monetize their gains and maintain continuous control over compromised devices.

Additional information:Microsoft stated that these types of Trojans do not only target the money transfer process, but also directly collect mnemonic phrases and private keys. Once this information is leaked, attackers can bypass the original device and directly access the relevant wallet.

Tip
$0
Like
0
Save
0
Views 764
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Microsoft warns of new encrypted clipboard Trojan activity
Microsoft has disclosed a new encrypted clipboard trojan campaign that allows attackers to deliver malware via USB, replacing wallet addresses and mnemonic phrases.
U.Today
·2026-06-18 18:49:17
179
Microsoft warns new clipboard trojan has backdoor capabilities
Microsoft says a new encrypted clipboard trojan has backdoor capabilities that can replace wallet addresses and steal mnemonic phrases.
Cryptonews
·2026-06-18 19:20:28
921
Microsoft discovers USB worm that steals encrypted wallets
Microsoft says a Windows malware that spreads via USB monitors the clipboard, steals sensitive information from encrypted wallets, and replaces transfer addresses.
CoinDesk
·2026-06-19 17:01:46
703
Kaspersky claims Steam wallpaper packs were used to steal encrypted wallets.
Kaspersky Lab claims that some wallpaper packs on the Steam Workshop have been used to spread malware that steals information, including encrypted wallet details.
Decrypt
·2026-06-19 23:11:30
787
Two Texas brothers admit to carrying out $8 million encrypted kidnapping.
Two Texas men have pleaded guilty to a cryptocurrency kidnapping and robbery involving more than $8 million, a case that has once again drawn attention to the rise of "wrench attacks."
Decrypt
·2026-06-19 22:50:57
562