Microsoft Warns of CryptoBandits Malware Targeting USB Drives to Compromise Crypto Wallets
Microsoft has identified a new malware strain, CryptoBandits, that exploits USB storage devices to hijack cryptocurrency transactions. The malicious software, active since February 2026, infiltrates systems through Windows shortcut files and targets self-custody wallet workflows.
The malware operates with surgical precision—monitoring clipboards every 500 milliseconds for seed phrases, private keys, and wallet addresses. It alters destination addresses during transactions and exfiltrates sensitive data through Tor networks. Hardware wallets remain vulnerable if connected to compromised endpoints during transaction signing.
This attack vector combines USB propagation with sophisticated clipboard hijacking, representing an evolution of earlier threats like ClipBanker. Security teams emphasize the importance of manual address verification and air-gapped signing procedures as countermeasures.
Log in to Reply
Log in to comment your thoughtsComments
Related Articles
|Square
Get the BTCC app to start your crypto journey
Get started today Scan to join our 100M+ users