On June 17, 2026, Microsoft disclosed the CryptoBandits campaign, a Windows based cryptocurrency clipper active since February 2026 that combines clipboard hijacking, seed phrase and private key theft, a bundled Tor p... The clipper monitors the clipboard every 500 milliseconds, replaces copied wallet addresses with...
Research answer

Create a landscape editorial hero image for this Studio Global article: What is the CryptoBandits malware campaign disclosed by Microsoft in June 2026, including its clipboard-hijacking mechanism targeting Bitcoi. Article summary: On June 17, 2026, Microsoft disclosed a Windows-based cryptocurrency clipper campaign active since February 2026, tracked with CryptoBandits-related detections [2][1]. The malware combines clipboard hijacking, seed phras. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
On June 17, 2026, Microsoft disclosed a Windows-based cryptocurrency clipper campaign active since February 2026, tracked with CryptoBandits-related detections . The malware combines clipboard hijacking, seed phrase and private key theft, a bundled Tor proxy, and worm-like USB propagation to steal cryptocurrency across connected and air-gapped environments
.
Clipboard-hijacking mechanism: The malware runs as a script-based payload via WScript and ActiveXObject . It monitors the clipboard roughly every 500 milliseconds, replacing copied cryptocurrency wallet addresses such as Bitcoin, Ethereum, Tron, Monero, and others with attacker-controlled addresses
. It also extracts seed phrases and private keys matching wallet-related patterns
.
Tor-based C2 evasion: The malware launches a renamed Tor binary (ugate.exe) in a hidden window, waits about 60 seconds for Tor to bootstrap, generates a victim GUID, and registers the infected device with a hidden-service command-and-control server . C2 communication flows through the local Tor SOCKS5 proxy on localhost:9050, helping avoid conventional IP-based infrastructure
.
Worm-like USB propagation: Initial infection occurs through malicious .lnk shortcut files distributed on USB storage devices . The
.lnk stages a worm component that checks for existing infection and, if absent, fetches the payload from the C2 over Tor . This mechanism can allow the malware to spread across air-gapped environments when infected USB drives are moved between machines
.
Additional capabilities: The malware uploads screenshots through Tor and can execute arbitrary attacker-supplied code at runtime if the C2 returns an EVAL response .
Microsoft Defender Experts recommend the following mitigations and hunting steps :
.lnk execution from removable drives via Group Policy wscript.exe and cscript.exe curl, PowerShell, or cmd.exe The CryptoBandits campaign fits into a broader set of reported cryptocurrency clipper and clipboard-hijacking activity . Other notable clipper operations reported around this period include:
Pro.exe / peeek.exe Taken together, these reports show clipper malware activity spanning script-driven Windows payloads, Tor-enabled infrastructure, USB-based propagation, social-platform distribution, and Linux-focused clipboard hijacking .
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On June 17, 2026, Microsoft disclosed the CryptoBandits campaign, a Windows based cryptocurrency clipper active since February 2026 that combines clipboard hijacking, seed phrase and private key theft, a bundled Tor p...
On June 17, 2026, Microsoft disclosed the CryptoBandits campaign, a Windows based cryptocurrency clipper active since February 2026 that combines clipboard hijacking, seed phrase and private key theft, a bundled Tor p... The clipper monitors the clipboard every 500 milliseconds, replaces copied wallet addresses with attacker addresses, and also extracts seed phrases and private keys matching wallet patterns [2].