New USB Worm Hijacks Cryptocurrencies via Clipboard Manipulation!
Hamid Siddiqui
News
No image for this briefing
Microsoft has uncovered a USB worm, Trojan:Win32/CryptoBandits.A, active since February 2026, that hijacks clipboards to swap cryptocurrency wallet addresses. It spreads through infected USB drives, hiding original files with shortcuts. The malware deploys a Tor client to avoid detection while capturing sensitive information. It targets various cryptocurrencies and can execute remote commands, showcasing advanced evasion techniques. Microsoft recommends disabling AutoRun and monitoring for suspicious network connections.