• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: Microsoft warns crypto clipper now acts like backdoor
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

Microsoft warns crypto clipper now acts like backdoor

Crypto
Last updated: June 19, 2026 12:08 am
Crypto
Published: June 19, 2026
Share
Microsoft warns crypto clipper now acts like backdoor

Microsoft Threat Intelligence has warned of a Windows-based crypto clipper campaign that has affected users since February 2026. Summary Microsoft says CryptoBandits uses Tor-routed communication, wallet replacement, screenshots, and remote code execution on Windows. The malware spreads through malicious shortcut files and creates more infected shortcuts from legitimate files. Security teams should hunt linked behaviors, not isolated alerts, to catch this attack chain early. In a Microsoft blog, researchers said the malware steals clipboard data, replaces wallet addresses, and searches for valuable crypto information. The company said Microsoft Defender Antivirus detects the threat as Trojan:Win32/CryptoBandits.A. In an X post, Microsoft said the campaign combines clipboard theft, wallet address replacement, worm-like behavior, and Tor-based communication. Malware spreads through shortcut files Microsoft said the attack starts with malicious .lnk shortcut files. These files can arrive through USB storage devices and launch a worm component on infected Windows systems. Once active, the malware creates more malicious shortcuts from legitimate files found on the device. Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices.…— Microsoft Threat Intelligence (@MsftSecIntel) June 17, 2026 The worm also sets up scheduled tasks for persistence. This allows the malware to keep running after restart and gives attackers a longer window to monitor the device. Microsoft said the threat uses script-based tools rather than a large installer, making simple file-based detection harder. Tor hides command traffic The clipper deploys a portable Tor client and routes traffic through a local SOCKS5 proxy. Microsoft said the malware uses localhost:9050 and .onion command-and-control domains to reduce normal DNS visibility and make blocking harder. The malware checks the clipboard about every 500 milliseconds. It looks for seed phrases, private keys, and crypto wallet addresses. If it finds a wallet address, it can replace it with an attacker-controlled address. If it finds a seed phrase or private key, it can send the data through Tor. Backdoor features raise risk Microsoft said the campaign goes beyond basic wallet address switching. The malware can upload screenshots, contact a hidden command server, and run attacker-supplied code through an EVAL command. That turns a crypto stealer into a lightweight backdoor. The company said, “defenders should hunt for correlated behaviors rather than investigate isolated events.” It advised teams to watch for script engines launching curl, cmd.exe, PowerShell, or unexpected files, especially when paired with localhost:9050 traffic. Crypto users remain frequent targets As crypto.news reported earlier, StilachiRAT also targeted crypto wallets and monitored clipboard activity. That Microsoft-linked warning covered malware that could scan browser wallets and extract stored data. According to an earlier crypto.news report, SparkCat malware used image scanning to search for wallet seed phrases in screenshots. crypto.news previously reported that Binance warned about clipper malware that replaced copied wallet addresses with attacker-controlled ones. The new Microsoft report shows that clipper malware is becoming more layered. It no longer only waits for users to copy a wallet address. It can spread, hide traffic through Tor, steal wallet data, capture screens, and keep access to the system.

Bitcoin’s Unstoppable Surge: 6th ATH in 48 Hours—What’s Next?
Unlock the Secrets: OS2 Launch Ignites Record OpenSea User Surge
Democrats Urgently Seek Trump, Musk Crypto Secrets: What They Fear Inside?
Zoth Heist: $8.4M Gone: Zoth’s Dark Secret
Unlock New Wealth: Centrifuge Tokenizes Real Assets on EVM Now!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Market Order vs Limit Order: How to actually place a crypto trade Market Order vs Limit Order: How to actually place a crypto trade
Next Article XRP is already settling Wall Street's treasuries XRP is already settling Wall Street's treasuries

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.