Threat reportMalwareTL-2026-0854
CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits)
CryptoBandits Windows Crypto-Clipper Campaign (TL-2026-0854), also tracked as CryptoBandits, is a high-severity malware campaign, first published 2026-06-18. It has no confirmed attribution, affects Microsoft Windows, maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1048.002), and is covered by 9 detection rules and 40 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-0854
- Threat ID
- TL-2026-0854
- Also known as
- CryptoBandits, Crypto Clipper (Microsoft)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, financial, consumer, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in CryptoBandits Windows Crypto-Clipper Campaign
Malware and tooling: CryptoBandits, Tor hidden-service C2
How CryptoBandits Windows Crypto-Clipper Campaign works
Microsoft Defender Experts have tracked a Windows cryptocurrency clipper campaign since February 2026 that propagates via USB-distributed LNK worm files and communicates over a bundled Tor client to a hidden-service C2. The malware (detected as Trojan:Win32/CryptoBandits) performs ~500ms clipboard monitoring to steal seed phrases and private keys, substitutes copied wallet addresses with attacker-controlled ones, exfiltrates screenshots over Tor, and supports runtime code execution via an EVAL command, turning a financially motivated stealer into a lightweight backdoor.
Since February 2026, Microsoft Defender Experts have tracked an active cryptocurrency clipper campaign affecting Windows users, with roughly 9,000 infections traced to the operation. Microsoft Defender Antivirus detects the threat family as Trojan:Win32/CryptoBandits (with .A/.B and JS variants) alongside several behavioral detections.
Initial access occurs through malicious Windows Shortcut (.lnk) files distributed on USB storage devices. When a victim plugs in an infected USB device, a worm component scans for common document types (DOC, XLSX, PDF), hides the legitimate files, and creates LNK files bearing the same names to trick the user into executing the payload. The LNK chain drops a JavaScript stager under C:\Users\Public\Documents in randomly named 5-character folders/scripts, executed via Windows Script Host and ActiveX-driven logic. The worm first checks whether the machine is already infected and only fetches the remote payload if not present.
For command-and-control, the malware deploys a portable Tor client renamed ugate.exe, launches it in a hidden window, waits roughly 60 seconds for the Tor circuit to bootstrap, and routes all traffic through a local SOCKS5 proxy at localhost:9050 to reach .onion hidden-service C2 servers. The device registers via a GUID heartbeat and polls C2 endpoints (/route.php for beacon/commands, /recvf.php for screenshot upload, /stub.php for payload download, output written to 'cfile'). Victim-to-C2 actions include GUID (heartbeat), SEED (seed phrase), PKEY (private key), REPL (address-replacement notice) and GOOD (legacy/fallback). If the C2 returns an EVAL response, the malware executes attacker-supplied JScript at runtime, providing arbitrary remote code execution.
The clipper monitors the clipboard roughly every 500 milliseconds, parsing it for BIP39 seed phrases (12/24-word), Ethereum private keys, Bitcoin WIF private keys, and a wide range of wallet-address formats (Bitcoin legacy/P2SH/Taproot/Bech32, Tron, Monero). When a destination wallet address is detected, it is silently replaced with an attacker-controlled address so funds are diverted on the next transaction (financial theft). The malware also captures five screenshots ten seconds apart for wallet context and uploads them over Tor.
Persistence is achieved through scheduled tasks for both the worm and stealer components; a scheduled task fires every 30 minutes to maintain persistence from the first step. Defense-evasion behavior includes masquerading (renamed Tor binary, document-impersonating LNKs), hidden files/window, obfuscated scripts, Defender process/path exclusion behaviors, and an anti-analysis check that queries running processes and exits if Task Manager is detected. No CVE is associated; this is a malware/TTP disclosure. The strongest defensive signals are behavioral: script interpreters spawning suspicious children, localhost:9050 SOCKS proxy usage, PowerShell screen-capture commands, and clipboard inspection / crypto-address replacement.
MITRE ATT&CK techniques used in TL-2026-0854
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1564.001 Hidden Files and Directories
Exfiltration
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Persistence
Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Initial Access
T1091 Replication Through Removable Media
Collection
T1113 Screen Capture; T1115 Clipboard Data
Impact
T1565.001 Stored Data Manipulation; T1657 Financial Theft
defense-impairment
Affected products and versions in CryptoBandits Windows Crypto-Clipper Campaign
- Microsoft — Windows
Vulnerable versions: Windows (all supported desktop versions running Windows Script Host)
Remediation for CryptoBandits Windows Crypto-Clipper Campaign
Immediate actions
- Block USB autorun and restrict removable-media execution via Group Policy / device control
- Hunt for and terminate the renamed Tor client ugate.exe and any process opening localhost:9050
- Inspect and remove scheduled tasks that launch JScript/WSH payloads from C:\Users\Public\Documents
- Block outbound Tor traffic at the network egress (Tor entry-node lists, SOCKS5 on 9050)
- Treat any wallet copied/pasted on a potentially infected host as compromised; rotate keys and move funds from exposed wallets
Workarounds
- Configure Microsoft Defender ASR rules to block executable content from email/USB and obfuscated script execution
- Show file extensions and disable hidden-item concealment so swapped LNK lures are visible
- Use hardware wallets with on-device address verification to defeat clipboard substitution
Longer-term hardening
- Deploy EDR with behavioral detection for clipboard inspection and crypto-address replacement
- Enforce application control (WDAC/AppLocker) to block wscript/cscript/mshta execution of user-writable scripts
- Disable Windows Script Host where not required
- Enable tamper protection so malware cannot add Defender process/path exclusions
- User awareness training on USB-borne LNK lures and verifying wallet addresses out-of-band before transacting
Timeline of CryptoBandits Windows Crypto-Clipper Campaign
- Clipper begins ~500ms clipboard monitoring, substituting copied wallet addresses and exfiltrating seed phrases, private keys, and screenshots over Tor.
- Infected hosts deploy the renamed portable Tor client (ugate.exe) and register with .onion hidden-service C2 servers over a localhost:9050 SOCKS5 proxy.
- USB worm component begins hiding DOC/XLSX/PDF files and creating same-named LNK lures to drive execution and self-propagate across removable media.
- Earliest activity of the CryptoBandits cryptocurrency clipper campaign tracked by Microsoft Defender Experts; malicious .lnk payloads begin spreading via USB storage devices.
- Microsoft Defender Antivirus signatures published: Trojan:Win32/CryptoBandits.A/.B, Trojan:JS/CryptoBandits.A/.B and related behavioral detections.
- Microsoft Security Blog publishes 'Crypto Clipper uses Tor and worm-like propagation for persistence and control,' detailing TTPs, detections, and IOCs (~9,000 infections).
- Threat ingested into the Threadlinqs Intelligence Platform as TL-2026-0854 for detection-coverage development.
- The Hacker News and other outlets report on Microsoft's disclosure of the Windows clipper USB LNK worm and Tor-based C2 campaign.
Sources cited for CryptoBandits Windows Crypto-Clipper Campaign
- Crypto Clipper uses Tor and worm-like propagation for persistence and control
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
- Microsoft warns of USB worm-like malware using Tor for stealth
- USB Shortcut Malware Uses Tor SOCKS Backdoor to Steal Cryptocurrency, Microsoft Warns
- Microsoft Threat Intelligence (MsftSecIntel) campaign disclosure thread
- Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
- Crypto Clipper uses Tor and worm-like propagation for persistence and control (Malware.news mirror)
Detection coverage for TL-2026-0854
As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0854 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0854
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.