Microsoft Threat Intelligence has warned of a Windows-based crypto clipper campaign affecting users since February 2026. The malware, called CryptoBandits, uses Tor-routed communication, wallet replacement, screenshots, and remote code execution on Windows. It spreads through malicious shortcut files and steals clipboard data, replacing wallet addresses. Security teams should look for linked behaviors to catch this attack chain early.

Leave a Reply