# CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2 (Trojan:Win32/CryptoBandits)

> Microsoft Defender Experts have tracked a Windows cryptocurrency clipper campaign since February 2026 that propagates via USB-distributed LNK worm files and communicates over a bundled Tor client to a hidden-service C2. The malware (detected as Trojan:Win32/CryptoBandits) performs ~500ms clipboard monitoring to steal seed phrases and private keys, substitutes copied wallet addresses with attacker-controlled ones, exfiltrates screenshots over Tor, and supports runtime code execution via an EVAL command, turning a financially motivated stealer into a lightweight backdoor.

- **Published:** 2026-06-18T00:00:00Z
- **Last reviewed:** 2026-06-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0854
- **ID:** TL-2026-0854
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Since February 2026, Microsoft Defender Experts have tracked an active cryptocurrency clipper campaign affecting Windows users, with roughly 9,000 infections traced to the operation. Microsoft Defender Antivirus detects the threat family as Trojan:Win32/CryptoBandits (with .A/.B and JS variants) alongside several behavioral detections.

Initial access occurs through malicious Windows Shortcut (.lnk) files distributed on USB storage devices. When a victim plugs in an infected USB device, a worm component scans for common document types (DOC, XLSX, PDF), hides the legitimate files, and creates LNK files bearing the same names to trick the user into executing the payload. The LNK chain drops a JavaScript stager under C:\Users\Public\Documents in randomly named 5-character folders/scripts, executed via Windows Script Host and ActiveX-driven logic. The worm first checks whether the machine is already infected and only fetches the remote payload if not present.

For command-and-control, the malware deploys a portable Tor client renamed ugate.exe, launches it in a hidden window, waits roughly 60 seconds for the Tor circuit to bootstrap, and routes all traffic through a local SOCKS5 proxy at localhost:9050 to reach .onion hidden-service C2 servers. The device registers via a GUID heartbeat and polls C2 endpoints (/route.php for beacon/commands, /recvf.php for screenshot upload, /stub.php for payload download, output written to 'cfile'). Victim-to-C2 actions include GUID (heartbeat), SEED (seed phrase), PKEY (private key), REPL (address-replacement notice) and GOOD (legacy/fallback). If the C2 returns an EVAL response, the malware executes attacker-supplied JScript at runtime, providing arbitrary remote code execution.

The clipper monitors the clipboard roughly every 500 milliseconds, parsing it for BIP39 seed phrases (12/24-word), Ethereum private keys, Bitcoin WIF private keys, and a wide range of wallet-address formats (Bitcoin legacy/P2SH/Taproot/Bech32, Tron, Monero). When a destination wallet address is detected, it is silently replaced with an attacker-controlled address so funds are diverted on the next transaction (financial theft). The malware also captures five screenshots ten seconds apart for wallet context and uploads them over Tor.

Persistence is achieved through scheduled tasks for both the worm and stealer components; a scheduled task fires every 30 minutes to maintain persistence from the first step. Defense-evasion behavior includes masquerading (renamed Tor binary, document-impersonating LNKs), hidden files/window, obfuscated scripts, Defender process/path exclusion behaviors, and an anti-analysis check that queries running processes and exits if Task Manager is detected. No CVE is associated; this is a malware/TTP disclosure. The strongest defensive signals are behavioral: script interpreters spawning suspicious children, localhost:9050 SOCKS proxy usage, PowerShell screen-capture commands, and clipboard inspection / crypto-address replacement.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1204.002 Malicious File
- T1059 Command and Scripting Interpreter
- T1059.007 JavaScript
- T1059.001 PowerShell
- T1053.005 Scheduled Task
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1564.001 Hidden Files and Directories
- T1685 Disable or Modify Tools
- T1057 Process Discovery
- T1115 Clipboard Data
- T1113 Screen Capture
- T1090.003 Multi-hop Proxy
- T1573 Encrypted Channel
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1657 Financial Theft
- T1565.001 Stored Data Manipulation

## Sources

- [Crypto Clipper uses Tor and worm-like propagation for persistence and control](https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/)
- [Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2](https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html)
- [Microsoft warns of USB worm-like malware using Tor for stealth](https://cyberinsider.com/microsoft-warns-of-usb-worm-like-malware-using-tor-for-stealth/)
- [USB Shortcut Malware Uses Tor SOCKS Backdoor to Steal Cryptocurrency, Microsoft Warns](https://windowsnews.ai/article/usb-shortcut-malware-uses-tor-socks-backdoor-to-steal-cryptocurrency-microsoft-warns.427549)
- [Microsoft Threat Intelligence (MsftSecIntel) campaign disclosure thread](https://x.com/MsftSecIntel/status/2067386600670089699)
- [Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper](https://cybersecuritynews.com/malware-campaign-deliver-crypto-clipper/)
- [Crypto Clipper uses Tor and worm-like propagation for persistence and control (Malware.news mirror)](https://malware.news/t/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/108000)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0854
