Microsoft Finds USB Worm Swapping Crypto Wallet Addresses

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Microsoft identified malware it dubs a "crypto clipper" (Trojan:Win32/CryptoBandits) that has been spreading via infected USB drives to target Windows crypto wallets since February.
- The worm installs through malicious .lnk shortcut files and monitors the Windows clipboard every 500 milliseconds for seed phrases, private keys, and recipient wallet addresses for Bitcoin and Ethereum.
- Stolen clipboard data is exfiltrated over the Tor network to attacker-controlled command-and-control servers, alongside five screenshots taken ten seconds apart.
- When a user copies a recipient address to send funds, the malware silently replaces it with an attacker-controlled address before the user pastes, diverting the transfer without any visible cue.
- The worm propagates by scanning any newly inserted clean USB drive for ordinary files like Word docs, Excel sheets, and PDFs, then replacing them with identically named malicious shortcuts to repeat the cycle.
- Microsoft recommends disabling AutoRun, blocking .lnk execution on removable media via group policy, restricting script hosts like wscript.exe and cscript.exe, and published indicators of compromise including file hashes and .onion domains.
Why it matters: This malware uses a physical USB vector rather than internet downloads, meaning any Windows user who plugs in an infected stick is exposed — even those who consider themselves careful online. The silent address-swap means a routine copy-paste transfer can be hijacked with zero visible warning, and Tor-based exfiltration evades standard network monitoring. Microsoft's published IOCs — file hashes and .onion C2 domains — give security teams a concrete checklist to audit their networks immediately.
Ask SkimNews



