Microsoft discovered malware that steals cryptocurrency via USB drives.
The malware, called CryptoBandits, spreads through infected USB flash drives and targets Windows users.
After launching a malicious shortcut file, the malware monitors the clipboard every 0.5 seconds. It steals seed phrases and private keys, takes screenshots, and sends collected data to attackers through Tor Project.
When a user copies a wallet address for a transfer, the malware may silently replace it with an attacker-controlled address.
It also propagates itself by infecting additional USB drives and replacing documents, spreadsheets, and PDF files with malicious shortcut files using the same names.
Microsoft recommends:
disabling USB autorun;
avoiding suspicious .lnk files;
verifying wallet addresses before confirming transactions.
The malware, called CryptoBandits, spreads through infected USB flash drives and targets Windows users.
After launching a malicious shortcut file, the malware monitors the clipboard every 0.5 seconds. It steals seed phrases and private keys, takes screenshots, and sends collected data to attackers through Tor Project.
When a user copies a wallet address for a transfer, the malware may silently replace it with an attacker-controlled address.
It also propagates itself by infecting additional USB drives and replacing documents, spreadsheets, and PDF files with malicious shortcut files using the same names.
Microsoft recommends:
disabling USB autorun;
avoiding suspicious .lnk files;
verifying wallet addresses before confirming transactions.