The Latest Crypto News
Tuesday, 28 July 2026 BTC -- / --
🔍

Microsoft Warns of Crypto Clipper Malware via Tor

Make The Latest Crypto News preferred on Google
Microsoft logo, Tor onion icon, and Bitcoin coin beside a malware warning symbol.
Microsoft logo, Tor onion icon, and Bitcoin coin beside a malware warning symbol.

Microsoft has raised the alarm over an advanced form of malware that specifically targets cryptocurrency users on Windows. Active since February 2026, this so-called crypto clipper is designed to steal wallet addresses, seed phrases and private keys. Microsoft Threat Intelligence and Microsoft Defender Experts are now bringing the threat to light.

How the malware works

The clipper spreads via malicious shortcut files (.lnk files) and USB sticks. Once active, the programme uses Windows Script Host and ActiveX to launch a Tor proxy, after which it connects to hidden C2 servers via the Tor network. What makes this malware particularly dangerous is that it does not follow a traditional installation process and does not use a visible IP address, making it harder to detect.

The malware then carries out multiple attacks at once: it reads clipboard data, takes screenshots, intercepts seed phrases and private keys, and replaces crypto wallet addresses. The latter is especially insidious: when you copy and paste a wallet address, the malware silently replaces it with an address belonging to the attacker. You then send your crypto to the wrong person without realising it. It is therefore wise to always double-check which crypto wallet address you are actually sending to.

Detection and what you can do

Microsoft Defender Antivirus now recognises the malware as Trojan:Win32/CryptoBandits.A. Users who keep their Windows security up to date are therefore better protected against this specific threat. Nevertheless, vigilance remains important, because the technique behind the clipper is sophisticated enough to have previously flown under the radar.

The combination of clipboard theft, screenshots and the replacement of wallet addresses makes this a versatile piece of malware that combines financial theft with capabilities for remote access to your system. So ensure your software is always updated, avoid using unknown USB sticks and be alert to suspicious shortcuts. Preferably use a reliable hardware wallet to protect your digital assets.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Altcoin News

More news ›