Threat reportMalwareTL-2026-0854

CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits)

highACTIVE

CryptoBandits Windows Crypto-Clipper Campaign (TL-2026-0854), also tracked as CryptoBandits, is a high-severity malware campaign, first published 2026-06-18. It has no confirmed attribution, affects Microsoft Windows, maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1048.002), and is covered by 9 detection rules and 40 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0854

Threat ID
TL-2026-0854
Also known as
CryptoBandits, Crypto Clipper (Microsoft)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial, consumer, technology
Target regions
Global
Detection rules
9
Indicators of compromise
40

Malware and tooling in CryptoBandits Windows Crypto-Clipper Campaign

Malware and tooling: CryptoBandits, Tor hidden-service C2

How CryptoBandits Windows Crypto-Clipper Campaign works

Microsoft Defender Experts have tracked a Windows cryptocurrency clipper campaign since February 2026 that propagates via USB-distributed LNK worm files and communicates over a bundled Tor client to a hidden-service C2. The malware (detected as Trojan:Win32/CryptoBandits) performs ~500ms clipboard monitoring to steal seed phrases and private keys, substitutes copied wallet addresses with attacker-controlled ones, exfiltrates screenshots over Tor, and supports runtime code execution via an EVAL command, turning a financially motivated stealer into a lightweight backdoor.

Since February 2026, Microsoft Defender Experts have tracked an active cryptocurrency clipper campaign affecting Windows users, with roughly 9,000 infections traced to the operation. Microsoft Defender Antivirus detects the threat family as Trojan:Win32/CryptoBandits (with .A/.B and JS variants) alongside several behavioral detections.

Initial access occurs through malicious Windows Shortcut (.lnk) files distributed on USB storage devices. When a victim plugs in an infected USB device, a worm component scans for common document types (DOC, XLSX, PDF), hides the legitimate files, and creates LNK files bearing the same names to trick the user into executing the payload. The LNK chain drops a JavaScript stager under C:\Users\Public\Documents in randomly named 5-character folders/scripts, executed via Windows Script Host and ActiveX-driven logic. The worm first checks whether the machine is already infected and only fetches the remote payload if not present.

For command-and-control, the malware deploys a portable Tor client renamed ugate.exe, launches it in a hidden window, waits roughly 60 seconds for the Tor circuit to bootstrap, and routes all traffic through a local SOCKS5 proxy at localhost:9050 to reach .onion hidden-service C2 servers. The device registers via a GUID heartbeat and polls C2 endpoints (/route.php for beacon/commands, /recvf.php for screenshot upload, /stub.php for payload download, output written to 'cfile'). Victim-to-C2 actions include GUID (heartbeat), SEED (seed phrase), PKEY (private key), REPL (address-replacement notice) and GOOD (legacy/fallback). If the C2 returns an EVAL response, the malware executes attacker-supplied JScript at runtime, providing arbitrary remote code execution.

The clipper monitors the clipboard roughly every 500 milliseconds, parsing it for BIP39 seed phrases (12/24-word), Ethereum private keys, Bitcoin WIF private keys, and a wide range of wallet-address formats (Bitcoin legacy/P2SH/Taproot/Bech32, Tron, Monero). When a destination wallet address is detected, it is silently replaced with an attacker-controlled address so funds are diverted on the next transaction (financial theft). The malware also captures five screenshots ten seconds apart for wallet context and uploads them over Tor.

Persistence is achieved through scheduled tasks for both the worm and stealer components; a scheduled task fires every 30 minutes to maintain persistence from the first step. Defense-evasion behavior includes masquerading (renamed Tor binary, document-impersonating LNKs), hidden files/window, obfuscated scripts, Defender process/path exclusion behaviors, and an anti-analysis check that queries running processes and exits if Task Manager is detected. No CVE is associated; this is a malware/TTP disclosure. The strongest defensive signals are behavioral: script interpreters spawning suspicious children, localhost:9050 SOCKS proxy usage, PowerShell screen-capture commands, and clipboard inspection / crypto-address replacement.

MITRE ATT&CK techniques used in TL-2026-0854

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1564.001 Hidden Files and Directories

Exfiltration

T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

Persistence

T1053.005 Scheduled Task

Discovery

T1057 Process Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Initial Access

T1091 Replication Through Removable Media

Collection

T1113 Screen Capture; T1115 Clipboard Data

Impact

T1565.001 Stored Data Manipulation; T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CryptoBandits Windows Crypto-Clipper Campaign

  • Microsoft — Windows
    Vulnerable versions: Windows (all supported desktop versions running Windows Script Host)

Remediation for CryptoBandits Windows Crypto-Clipper Campaign

Immediate actions

  • Block USB autorun and restrict removable-media execution via Group Policy / device control
  • Hunt for and terminate the renamed Tor client ugate.exe and any process opening localhost:9050
  • Inspect and remove scheduled tasks that launch JScript/WSH payloads from C:\Users\Public\Documents
  • Block outbound Tor traffic at the network egress (Tor entry-node lists, SOCKS5 on 9050)
  • Treat any wallet copied/pasted on a potentially infected host as compromised; rotate keys and move funds from exposed wallets

Workarounds

  • Configure Microsoft Defender ASR rules to block executable content from email/USB and obfuscated script execution
  • Show file extensions and disable hidden-item concealment so swapped LNK lures are visible
  • Use hardware wallets with on-device address verification to defeat clipboard substitution

Longer-term hardening

  • Deploy EDR with behavioral detection for clipboard inspection and crypto-address replacement
  • Enforce application control (WDAC/AppLocker) to block wscript/cscript/mshta execution of user-writable scripts
  • Disable Windows Script Host where not required
  • Enable tamper protection so malware cannot add Defender process/path exclusions
  • User awareness training on USB-borne LNK lures and verifying wallet addresses out-of-band before transacting

Timeline of CryptoBandits Windows Crypto-Clipper Campaign

  • Clipper begins ~500ms clipboard monitoring, substituting copied wallet addresses and exfiltrating seed phrases, private keys, and screenshots over Tor.
  • Infected hosts deploy the renamed portable Tor client (ugate.exe) and register with .onion hidden-service C2 servers over a localhost:9050 SOCKS5 proxy.
  • USB worm component begins hiding DOC/XLSX/PDF files and creating same-named LNK lures to drive execution and self-propagate across removable media.
  • Earliest activity of the CryptoBandits cryptocurrency clipper campaign tracked by Microsoft Defender Experts; malicious .lnk payloads begin spreading via USB storage devices.
  • Microsoft Defender Antivirus signatures published: Trojan:Win32/CryptoBandits.A/.B, Trojan:JS/CryptoBandits.A/.B and related behavioral detections.
  • Microsoft Security Blog publishes 'Crypto Clipper uses Tor and worm-like propagation for persistence and control,' detailing TTPs, detections, and IOCs (~9,000 infections).
  • Threat ingested into the Threadlinqs Intelligence Platform as TL-2026-0854 for detection-coverage development.
  • The Hacker News and other outlets report on Microsoft's disclosure of the Windows clipper USB LNK worm and Tor-based C2 campaign.

Sources cited for CryptoBandits Windows Crypto-Clipper Campaign

Detection coverage for TL-2026-0854

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0854 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0854

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats