• Advertise with us
  • Pricing
  • Submit News
Instagram Twitter Facebook Telegram Youtube Linkedin
EdaFace Newsfeed
EdaFace Newsfeed
  • News

    Main News

    • Crypto News
    • Bitcoin and BTC
    • Altcoin News
    • Security & Hacks
    • ICO & Token Sales
    • Interviews & Profiles

    Information

    • Press Release
    • Research Report
    • Regulations, Law & Policy
    • Community/Guest Post
    • Events & Conferences
    • Tutorials & Guides

    Market

    • Technical Analysis
    • Price Analysis
    • Cryptocurrency Price Prediction
    • DeFi (Decentralized Finance)
    • Mining & Staking

    Other Categories

    • NFTs & Digital Art
    • Opinion & Editorials
    • Tech Innovations
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
More
  • News
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
Reading: A new crypto threat targeting Windows users has emerged! What critical warnings did Microsoft make?
Share
Sign In
EdaFace Newsfeed
EdaFace Newsfeed
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
EdaFace Newsfeed > Latest News > Security & Hacks > A new crypto threat targeting Windows users has emerged! What critical warnings did Microsoft make?
Security & Hacks

A new crypto threat targeting Windows users has emerged! What critical warnings did Microsoft make?

vitalclick
Last updated: June 19, 2026 10:46 am
16 hours ago
Share
SHARE

Contents
How does malware work?What data does it target?Propagation method via USBMicrosoft’s security recommendations

Microsoft announced that it has detected a new malware that has been spreading via USB sticks since February and targeting the crypto asset wallets of people using Windows. While the company defined this threat as “crypto clipper”, it stated that the malware was tracked under the name Trojan:Win32/CryptoBandits in Microsoft Defender Antivirus.

How does malware work?

The attack starts with a malicious .lnk shortcut file on an infected USB drive. In Windows, these files are normally used to open a program, folder or file. However, when the user clicks on this shortcut, a worm-type malware is installed on the computer.

Once installed, the software executes two processes simultaneously. On the one hand, it constantly runs the actual code to collect data from crypto wallets, on the other hand, it waits for a clean USB device to be inserted into the same computer. Thus, it is not limited to a single system but can be spread across different portable devices.

According to Microsoft, the malware monitors clipboard data at regular intervals; It collects information such as seed phrase, private key and recipient address, and then transmits them to attackers over the Tor network. When the user copies an address for the transfer, this address can be replaced with the wallet address controlled by the attacker without being noticed.

What data does it target?

According to information provided by Microsoft, the malware checks the Windows clipboard approximately every 500 milliseconds. If the user copies the seed phrase or private key of wallets such as Bitcoin or Ethereum, this data is captured. It was also stated that the software took a total of five screenshots at 10-second intervals and sent them outside.



One of the most critical risks here is the silent change of transfer addresses. When the user copies a recipient address to send funds, the malware can replace this address with another address belonging to the attacker before the pasting stage. Since this change occurs without any visible warning, it becomes possible for the transaction to go to the wrong address.

Mini dictionary: Tor network is known as an open source structure that makes communication more confidential by routing internet traffic through different servers. It can also be used to hide command and control traffic from time to time during cyber attacks.

Propagation method via USB

The spreading mechanism of the malware also attracts attention. When a clean USB drive is inserted into the computer, the software scans regular files such as Word, Excel and PDF on this device. Then, it replaces these files with new shortcut files with the same names and infects the USB drive.

This method can lead users to think that files remain seemingly the same. Thus, the infection cycle continues by moving to new computers.

Microsoft’s security recommendations

Microsoft recommended turning off AutoRun for removable media, preventing .lnk files from running on USB drives via group policies, and limiting script runners such as wscript.exe and cscript.exe. The company also required security teams to scan its networks based on published indicators of compromise.

According to the statement, these indicators include file hashes and .onion domain names that are stated to be used on command and control servers. It was stated that customers using Microsoft Defender can query related activities, including connections made to the local Tor proxy server over port 9050.

Disclaimer: The information contained in this content is not investment advice. Please note that cryptocurrencies involve high volatility and therefore risk. It is recommended that you make your investment decisions based on your own research and risk assessments. You can review our Trust Center page for detailed information.

You Might Also Like

Bitcoin Losses And Bithumb Error Tightens Crypto Regulation In South Korea

Revolut Blocks $621 Million in Suspicious Transfers in 2023

Crypto Attacks Caused $313 Million in Losses in August

Cryptocurrency Exchange BingX Falls Victim of Hack Attack! $43 Million Stolen!

Cryptocurrency Privacy Statement from the US Treasury Department: New Approach to Legitimate Use

TAGGED:Security
Share This Article
Facebook Twitter Email Print
Previous Article Bitcoin Price Prediction Shows Breakout Forming as Coinbase CEO Calls $60K the Bottom and Pepeto Presale Hits $10.27M
Next Article Cardano Founder Discusses Exciting Japan Partnership
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Crypto Live Widget

Follow for Live Updates
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad imageAd image
Popular News
Why Ethereum is Poised to Explode to $4,600 Sooner Than You Think!
Five Altcoins With 100x Potential To Buy Now
ETF Approvals, Regulatory Frameworks, and Market Dynamics
Top News, Bitcoin and Altcoin Volatility, Major Hacks, and DeFi Investments
RCO Finance (RCOF) Captures The Future

Company

  • Vision
  • Mission
  • LitePaper
  • Whitepaper
  • Core Values
  • Branding
  • Teams
  • Career Listing
  • FAQ
  • Welfare Donations

Products

  • EDA Coin
  • Blockchain Literature
  • EdaFace Dex
  • EdaFace Mall
  • Listing Platforms
  • Newsfeed
  • NFT Marketplace
  • P2P Market
  • Scam Verification Centre
  • School of Crypto

Legal

  • Term of Use
  • Privacy Policy
  • Disclaimers
  • Contact Us
  • Chat Forun

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

EdaFace

About US

EdaFace is a user interface aggregator that brings all the various functionalities of the crypto industry onto a single platform! You can advertise, launch and crowdfund your crypto project via EdaFace Launchpad and Newsfeed.

Contact us: [email protected]

Follow us

Instagram Twitter Facebook Telegram Youtube Linkedin

Copyright © 2022 – 2026. EdaFace is a product of Emerging Digital Age (EDA) Pty Ltd. All Rights Reserved.

Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
EdaFace
Welcome Back!

Sign in to your account

Lost your password?