Microsoft Warns of Tor-Based Crypto Clipper Targeting Wallet Data
Microsoft Threat Intelligence and Microsoft Defender Experts said they identified a Windows-based crypto clipper that has affected users since February 2026. The malware spreads via malicious .lnk shortcuts and USB drives, launches a bundled Tor proxy through Windows Script Host and ActiveX, and connects to hidden-service C2 servers. It can steal clipboard data, exfiltrate seed phrases and private keys, capture screenshots, and replace crypto wallet addresses. Microsoft Defender Antivirus detects it as Trojan:Win32/CryptoBandits.A.
via x.com/WuBlockchain
Wait, USB drives? They got people with USB drives in 2026? Someone plugged in a random stick and lost their seed phrase, I genuinely need a minute. The Tor proxy through ActiveX pipeline is almost impressive as an archaeological dig, and yet here we are, wallets getting drained by tech from the XP era.
💧Rainbet.com the #1 Non-KYC Crypto Casino & Sportsbook @rainbetcom
💧 Exclusive Giveaways & Rewards USE CODE: evaders On Sign Up. If your location is restricted use a VPN.
💀 The Damage · 🔗 Read
Post #115
2.41K
