CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits) — Threadlinqs Intelligence
As of 2026-06-18, CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits) is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0854 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Microsoft Defender Experts have tracked a Windows cryptocurrency clipper campaign since February 2026 that propagates via USB-distributed LNK worm files and communicates over a bundled Tor client to a
Since February 2026, Microsoft Defender Experts have tracked an active cryptocurrency clipper campaign affecting Windows users, with roughly 9,000 infections traced to the operation. Microsoft Defender Antivirus detects the threat family as Trojan:Win32/CryptoBandits (with .A/.B and JS variants) alongside several behavioral detections.
Initial access occurs through malicious Windows Shortcut (.lnk) files distributed on USB storage devices. When a victim plugs in an infected USB device, a worm component scans for common document types (DOC, XLSX, PDF), hides the legitimate files, and creates LNK files bearing the same names to trick the user into executing the payload. The LNK chain drops a JavaScript stager under C:\Users\Public\Documents in randomly named 5-character folders/scripts, executed via Windows Script Host and ActiveX-driven logic. The worm first checks whether the machine is already infected and only fetches the remote payload if not present.
For command-and-control, the malware deploys a portable Tor client renamed ugate.exe, launches it in a hidden window, waits roughly 60 seconds for the Tor circuit to bootstrap, and routes all traffic through a local SOCKS5 proxy at localhost:9050 to reach .onion hidden-service C2 servers. The device registers via a GUID heartbeat and polls C2 endpoints (/route.php for beacon/commands, /recvf.php for screenshot upload, /stub.php for payload download, output written to 'cfile'). Victim-to-C2 actions include GUID (heartbeat), SEED (seed phrase), PKEY (private key), REPL (address-replacement notice) and GOOD (legacy/fallback). If the C2 returns an EVAL response, the malware executes attacker-supplied JScript at runtime, providing arbitrary remote code execution.
The clipper monitors the clipboard roughly every 500 milliseconds, parsing it for BIP39 seed phrases (12/24-word), Ethereum private keys, Bitcoin WIF private keys, and a wide range of wallet-address formats (Bitcoin legacy/P2SH/Taproot/Bech32, Tron, Monero). When a destination wallet address is detected, it is silently replaced with an attacker-controlled address so funds are diverted on the next transaction (financial theft). The malware also captures five screenshots ten seconds apart for wallet context and uploads them over Tor.
Persistence is achieved through scheduled tasks for both the worm and stealer components; a scheduled task fires every 30 minutes to maintain persistence from the first step. Defense-evasion behavior includes masquerading (renamed Tor binary, document-impersonating LNKs), hidden files/window, obfuscated scripts, Defender process/path exclusion behaviors, and an anti-analysis check that queries running processes and exits if Task Manager is detected. No CVE is associated; this is a malware/TTP disclosure. The strongest defensive signals are behavioral: script interpreters spawning suspicious children, localhost:9050 SOCKS proxy usage, PowerShell screen-capture commands, and clipboard inspection / crypto-address replacement.
Target sectors: cryptocurrency, financial, consumer, technology
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1091, T1204.002, T1059, T1059.007, T1059.001, T1053.005, T1027, T1036, T1564.001, T1562.001