๐Ÿ›‘ CryptoBandits malware has hit Windows users since February via USB drives. โšก The malware steals crypto wallet data and changes clipboard addresses to steal funds๐Ÿ›‘ CryptoBandits malware has hit Windows users since February via USB drives. โšก The malware steals crypto wallet data and changes clipboard addresses to steal funds

CryptoBandits malware hits Windows users via USB drives since February

2026/06/19 18:53
3๋ถ„ ์ฝ๊ธฐ
์ด ์ฝ˜ํ…์ธ ์— ๋Œ€ํ•œ ์˜๊ฒฌ์ด๋‚˜ ์šฐ๋ ค ์‚ฌํ•ญ์ด ์žˆ์œผ์‹œ๋ฉด crypto.news@mexc.com์œผ๋กœ ์—ฐ๋ฝ์ฃผ์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค

Microsoft has identified a new strain of malware targeting the cryptocurrency wallets of Windows users, spreading through USB drives since February. The company refers to this threat as a โ€œcrypto clipperโ€ and tracks it under the name Trojan:Win32/CryptoBandits in Microsoft Defender Antivirus.

How does the malware operate?

The attack begins with a malicious shortcut file (.lnk extension) placed on an infected USB drive. Although these files are typically used to open programs or folders in Windows, clicking on the compromised shortcut installs a worm-like malware onto the device.

After installation, the malware simultaneously carries out two key tasks. First, it perpetually runs its primary code to gather information from crypto wallets. Second, it continuously waits for a clean USB device to be connected to the same computer, enabling the infection to propagate across multiple portable devices and systems.

What data is targeted?

Microsoft notes that the malware scans the Windows clipboard roughly every 500 milliseconds. If a user copies a seed phrase or private key from a wallet such as Bitcoin or Ethereum, the software captures these sensitive details. The malware also takes up to five screenshots at ten-second intervals and transmits them externally.

One of the most critical risks is the silent replacement of transfer addresses. When users copy a recipient address to send funds, the malware can swap it out for an attackerโ€™s address just before it is pastedโ€”without any visible warningโ€”potentially diverting cryptocurrency to unauthorized hands.

Mini glossary: The Tor network is an open-source platform that enhances privacy by routing internet traffic through various servers. It is often used in cyberattacks to conceal command-and-control communication.

USB-based propagation method

The method of spreading via USB stands out as another notable feature. When a clean USB drive is connected to a compromised computer, the malware scans it for files like Word, Excel, and PDF documents. It then replaces these with similarly named shortcut files, thereby infecting the USB drive as well.

This tactic can mislead users into thinking their files are unchanged, allowing the infection cycle to continue as the compromised USB drive is connected to other devices, facilitating broader spread.

Microsoftโ€™s security recommendations

Microsoft recommends disabling the AutoRun feature for removable media, blocking the execution of .lnk files on USB drives via group policies, and restricting script hosts such as wscript.exe and cscript.exe. The company also urges IT teams to scan their networks for indicators of compromise that have been published.

Indicators include file hashes and .onion domain addresses reportedly linked to command-and-control servers. Customers with Microsoft Defender are further advised to check for suspicious connections to the local Tor proxy on port 9050 and review related activities within their systems.

The post CryptoBandits malware hits Windows users via USB drives since February appeared first on COINTURK NEWS.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

๋ฉด์ฑ… ์กฐํ•ญ: ๋ณธ ์‚ฌ์ดํŠธ์— ์žฌ๊ฒŒ์‹œ๋œ ๊ธ€๋“ค์€ ๊ณต๊ฐœ ํ”Œ๋žซํผ์—์„œ ๊ฐ€์ ธ์˜จ ๊ฒƒ์œผ๋กœ ์ •๋ณด ์ œ๊ณต ๋ชฉ์ ์œผ๋กœ๋งŒ ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋ฐ˜๋“œ์‹œ MEXC์˜ ๊ฒฌํ•ด๋ฅผ ๋ฐ˜์˜ํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹™๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ถŒ๋ฆฌ๋Š” ์›์ €์ž์—๊ฒŒ ์žˆ์Šต๋‹ˆ๋‹ค. ์ œ3์ž์˜ ๊ถŒ๋ฆฌ๋ฅผ ์นจํ•ดํ•˜๋Š” ์ฝ˜ํ…์ธ ๊ฐ€ ์žˆ๋‹ค๊ณ  ํŒ๋‹จ๋  ๊ฒฝ์šฐ, crypto.news@mexc.com์œผ๋กœ ์—ฐ๋ฝํ•˜์—ฌ ์‚ญ์ œ ์š”์ฒญ์„ ํ•ด์ฃผ์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. MEXC๋Š” ์ฝ˜ํ…์ธ ์˜ ์ •ํ™•์„ฑ, ์™„์ „์„ฑ ๋˜๋Š” ์‹œ์˜์ ์ ˆ์„ฑ์— ๋Œ€ํ•ด ์–ด๋– ํ•œ ๋ณด์ฆ๋„ ํ•˜์ง€ ์•Š์œผ๋ฉฐ, ์ œ๊ณต๋œ ์ •๋ณด์— ๊ธฐ๋ฐ˜ํ•˜์—ฌ ์ทจํ•ด์ง„ ์–ด๋– ํ•œ ์กฐ์น˜์— ๋Œ€ํ•ด์„œ๋„ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ณธ ์ฝ˜ํ…์ธ ๋Š” ๊ธˆ์œต, ๋ฒ•๋ฅ  ๋˜๋Š” ๊ธฐํƒ€ ์ „๋ฌธ์ ์ธ ์กฐ์–ธ์„ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉฐ, MEXC์˜ ์ถ”์ฒœ์ด๋‚˜ ๋ณด์ฆ์œผ๋กœ ๊ฐ„์ฃผ๋˜์–ด์„œ๋Š” ์•ˆ ๋ฉ๋‹ˆ๋‹ค.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel