• Advertise with us
  • Pricing
  • Submit News
Instagram Twitter Facebook Telegram Youtube Linkedin
EdaFace Newsfeed
EdaFace Newsfeed
  • News

    Main News

    • Crypto News
    • Bitcoin and BTC
    • Altcoin News
    • Security & Hacks
    • ICO & Token Sales
    • Interviews & Profiles

    Information

    • Press Release
    • Research Report
    • Regulations, Law & Policy
    • Community/Guest Post
    • Events & Conferences
    • Tutorials & Guides

    Market

    • Technical Analysis
    • Price Analysis
    • Cryptocurrency Price Prediction
    • DeFi (Decentralized Finance)
    • Mining & Staking

    Other Categories

    • NFTs & Digital Art
    • Opinion & Editorials
    • Tech Innovations
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
More
  • News
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
Reading: Microsoft detects new malware that has been changing crypto wallet addresses since February 2026
Share
Sign In
EdaFace Newsfeed
EdaFace Newsfeed
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
EdaFace Newsfeed > Latest News > Crypto News > Microsoft detects new malware that has been changing crypto wallet addresses since February 2026
Crypto News

Microsoft detects new malware that has been changing crypto wallet addresses since February 2026

vitalclick
Last updated: June 19, 2026 10:42 pm
5 hours ago
Share
SHARE

Contents
How the malware worksRecommended precautionsMicrosoft’s previous warnings and operations

Microsoft security researchers have revealed a new malware campaign targeting crypto assets that has been effective since February 2026. It was reported that the software, identified as Trojan:Win32/CryptoBandits.A, spread especially through USB memory sticks and replaced the copied wallet addresses with the addresses of the attackers in a short time. In addition to being a US-based technology company, Microsoft also has a large research team that monitors cyber security threats.

How the malware works

According to the information provided, the infection process begins by inserting a USB drive containing the malware into the computer. The software runs the malicious component via disguised shortcut files and can then spread a copy of itself to local storage devices. Once installed on the Windows system, it uses Tor-based proxy servers to hide its connection to the command servers.

The real risk occurs when the user makes a transfer. It was stated that the malware monitored the clipboard every 500 milliseconds and replaced the user’s copied wallet address with the attacker’s address within half a second. If the user does not verify the address manually, the amount sent can go directly to the attackers’ wallet.

According to the findings of Microsoft researchers, the software not only changes wallet addresses, but also tries to capture private keys and seed phrases by scanning local files.

Mini dictionary: Seed phrase is a backup phrase that helps save the crypto wallet and usually consists of 12 or 24 words. Interception of this phrase may lead to loss of control of the assets in the wallet.



Recommended precautions

Microsoft recommended reviewing daily usage habits against such attacks. It was recommended to turn off the AutoRun feature on Windows devices, not to use USB devices of unknown origin, and to check all characters in the wallet address one by one before giving transfer approval. It was also emphasized that hardware wallets, which work isolated from the internet connection, are one of the most reliable options for protecting seed phrase information.

Microsoft’s previous warnings and operations

The company has previously warned about other threats targeting crypto users. Among these, [email protected] And [email protected] There were malicious components hidden in two npm packages called . It was announced that the tools in question collected keyboard inputs and screenshots through a remote access malware and then leaked wallet credentials.

In May 2025, Microsoft spearheaded a globally coordinated operation and took comprehensive steps against the Lumma Stealer structuring, which has been stated to be active since late 2022. It was reported that 2,300 malicious domain names were seized within the scope of this operation, and the US Department of Justice intervened in the central control panel and dark network markets.

In the process carried out in line with the court decision, Microsoft’s Digital Crimes Unit seized 2,300 domain names, while Europol EC3 and Japan JC3 stopped the remaining servers in Europe and Asia.

Current findings show that malware spread through physical carriers has come to the fore again in terms of crypto security. In particular, the combination of the USB-based infection method and the address change technique targeting clipboard data makes careful verification processes even more important for individual investors.

Disclaimer: The information contained in this content is not investment advice. Please note that cryptocurrencies involve high volatility and therefore risk. It is recommended that you make your investment decisions based on your own research and risk assessments. You can review our Trust Center page for detailed information.

You Might Also Like

His Best Ripple and XRP Quotes

Ethereum Price Breakdown Ignites Fresh Bear Fears Across Crypto

Hong Kong to Issue First Stablecoin Licenses in Q1 as Crypto Race Heats Up

Cowen’s Cryptocurrency Predictions for 2024 and 2025

Breaking News: Fed Statements and BlackRock’s Latest Cryptocurrency Move

TAGGED:Cryptocurrency
Share This Article
Facebook Twitter Email Print
Previous Article FBI says it will expand operations as crypto-related fraud losses in the US rise to $11 billion
Next Article The Future of Wealth Preservation
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Crypto Live Widget

Follow for Live Updates
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad imageAd image
Popular News
Why Ethereum is Poised to Explode to $4,600 Sooner Than You Think!
Five Altcoins With 100x Potential To Buy Now
ETF Approvals, Regulatory Frameworks, and Market Dynamics
Top News, Bitcoin and Altcoin Volatility, Major Hacks, and DeFi Investments
RCO Finance (RCOF) Captures The Future

Company

  • Vision
  • Mission
  • LitePaper
  • Whitepaper
  • Core Values
  • Branding
  • Teams
  • Career Listing
  • FAQ
  • Welfare Donations

Products

  • EDA Coin
  • Blockchain Literature
  • EdaFace Dex
  • EdaFace Mall
  • Listing Platforms
  • Newsfeed
  • NFT Marketplace
  • P2P Market
  • Scam Verification Centre
  • School of Crypto

Legal

  • Term of Use
  • Privacy Policy
  • Disclaimers
  • Contact Us
  • Chat Forun

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

EdaFace

About US

EdaFace is a user interface aggregator that brings all the various functionalities of the crypto industry onto a single platform! You can advertise, launch and crowdfund your crypto project via EdaFace Launchpad and Newsfeed.

Contact us: [email protected]

Follow us

Instagram Twitter Facebook Telegram Youtube Linkedin

Copyright © 2022 – 2026. EdaFace is a product of Emerging Digital Age (EDA) Pty Ltd. All Rights Reserved.

Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
EdaFace
Welcome Back!

Sign in to your account

Lost your password?