Microsoft found malware that hijacks crypto wallets and spreads through USB sticks

Microsoft found malware that hijacks crypto wallets and spreads through USB sticks

Source: CoinDesk

Published:2026-06-19 08:48

BTC Price:$62654.1

#cryptosecurity #malware #cybersecurity

Analysis

Price Impact

Med

The news highlights a specific malware threat targeting crypto wallets via usb drives. while this is a serious security concern for individual users, it doesn't directly impact the underlying technology or adoption of major cryptocurrencies like bitcoin or ethereum. however, it could lead to temporary caution and increased security awareness among traders, potentially causing minor price fluctuations. stablecoins like usdt and usdc might see slightly increased demand if users move funds to perceived safer, centralized assets, though the impact would likely be limited.

Trustworthiness

High

Price Direction

Neutral

The news primarily focuses on a security vulnerability and a method of theft, not on fundamental changes to cryptocurrency value or adoption. while such events can cause short-term fear or caution, they typically do not alter the long-term price trajectory of major cryptocurrencies unless they indicate a systemic failure or a widespread loss of confidence, which is not the case here.

Time Effect

Short

The impact of this specific malware is likely to be short-lived. as security measures are implemented (as recommended by microsoft) and awareness increases, the effectiveness of this particular threat will diminish. the crypto market is constantly evolving with new threats and defenses, making this a transient concern.

Original Article:

Article Content:

Tech Microsoft found malware that hijacks crypto wallets and spreads through USB sticks The software intercepts shortcut files and directs them to install a worm that harvests private keys from the Windows clipboard and inserts its own destination wallet addresses when it detects a transfer. By Omkar Godbole | Edited by Sheldon Reback Jun 19, 2026, 8:48 a.m. 2 min read Make preferred on Share Share this article Copy link X icon X (Twitter) LinkedIn Facebook Email Make preferred on A worm that's been around since February propagates by USB drives. (Brina Blum/Unsplash) Summary Show The malware dubbed a “crypto clipper,” has been spreading via infected USB drives to target Windows users’ crypto wallets since February, according to Microsoft. Once installed through a malicious .lnk shortcut file, the worm known as Trojan:Win32/CryptoBandits monitors the clipboard for seed phrases, private keys and recipient addresses, exfiltrates data over the Tor network, and can silently swap in attacker-controlled wallet addresses. The malware propagates by replacing documents on clean USB drives with identically named shortcuts Microsoft urged users to disable AutoRun, block .lnk execution on USB media, restrict script hosts and check networks against published indicators of compromise. Malware that spreads via USB sticks has been infecting Windows personal computers and targeting crypto wallets since February, Microsoft said in a blog post. The firm calls the malware a "crypto clipper", and its Defender Antivirus identifies it as Trojan:Win32/CryptoBandits. The process starts with an infected USB drive containing a malicious shortcut, or link, file. In Windows, shortcut filenames end in ".lnk" and direct the operating system to open a specific program, folder or file stored elsewhere on your computer. When a user plugs in that drive and clicks the shortcut, a type of malware known as a "worm" is installed onto the PC. Once installed, it does two things: it constantly runs the actual crypto wallet-stealing code and simultaneously waits for a new, clean USB to be plugged into that same PC. The wallet-stealing component monitors Windows’ clipboard, the hidden temporary memory used for copy-and-paste operations, roughly every 500 milliseconds. When a user copies a crypto wallet seed phrase or a private key for a Bitcoin or Ethereum wallet, the malware captures that data and sends it to the attacker’s server over the Tor network, an open-source overlay that provides anonymous communication. It also takes five screenshots, ten seconds apart, and sends those along too. The risk doesn't end there. If a user copies a recipient address to send funds, the worm silently replaces it with an attacker-controlled address before the user pastes, so the transfer goes to the attacker without any visible cue. Lastly, the worm propagates when a clean USB drive is plugged into the computer. It scans the clean USB drive for ordinary files, Word docs, Excel sheets and PDFs, replaces them with new shortcut files using the same names and infects the drive. Then the cycle continues. Microsoft recommends disabling AutoRun for removable media, blocking .lnk file execution on USB drives via group policy and restricting script hosts such as wscript.exe and cscript.exe. Microsoft Defender customers can also run hunting queries to check for related activity, including connections to a local Tor proxy on port 9050. Microsoft published a list of indicators of compromise, including file hashes and .onion domains used as command-and-control servers, for security teams to check their networks against. Hack Crime Latest Crypto News 1 XRP falls 3% after losing $1.15 support as breakout attempt fades 3 hours ago 2 Live markets: Bitcoin has traded below its mining cost for five months, squeezing miners 3 hours ago 3 Bitcoin traders load up on bearish bets all the way down to $52,000 3 hours ago 4 Bitcoin falls below $63,000 as risk assets sell off and the week's bounce fades 4 hours ago 5 Ex-Celsius CEO Mashinsky gets U.S. CFTC ban in final resolution with regulator 13 hours ago 6 U.S. agencies seek stablecoin customer-ID rules akin to banks in new GENIUS Act pitch 15 hours ago 7 Ethereum Foundation loses another key leader as co-executive director Hsiao-Wei Wang resigns 17 hours ago 8 Crypto for Advisors: Trading the bitcoin cycle 17 hours ago 9 Algorand unveils roadmap to achieve quantum resistance by 2028 18 hours ago 10 CoinDesk 20 performance update: Stellar (XLM) jumps 10% while index declines 19 hours ago Latest Research CEX Volumes Drop to Lowest Since September 2024 as RWA Perps Hit Record High CEX Volumes Drop to Lowest Since September 2024 as RWA Perps Hit Record High In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. By CoinDesk Research Jun 15, 2026 In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. Why it matters : In May, combined exchange volumes fell 3.45% to $4.41T; the lowest since September 2024. RWA perpetual futures volumes rose 10.4% against the trend, hitting a new all-time high. View Full Report More From Tech Ethereum Foundation loses another key leader as co-executive director Hsiao-Wei Wang resigns Algorand unveils roadmap to achieve quantum resistance by 2028 Live markets: price action turns panicky in Saylor's STRC as bitcoin drops below $63,000