Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

BNB price breaks $600, can bulls trigger a rally to $635?

August 10, 2026

H100’s BTC Stash Soars as Empery Digital Dumps Bitcoin

August 10, 2026

Cardano Opens 2.5 Million ADA Funding Round for New Projects

August 10, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Crypto News

Microsoft Warns of USB-Spreading Crypto Malware Targeting Bitcoin and Ethereum Wallets

By WebDeskJuly 1, 20264 Mins Read
Microsoft Warns of USB-Spreading Crypto Malware Targeting Bitcoin and Ethereum Wallets
Share
Facebook Twitter LinkedIn Pinterest Email

All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.
  • Microsoft identified a crypto-targeting malware campaign active since February 2026.
  • The malware spreads through infected USB drives using malicious shortcut files.
  • It monitors clipboard activity and replaces copied wallet addresses with attacker-controlled destinations.
  • Bitcoin, Ethereum, Monero and Tron users are among the primary targets.
  • The malware also includes backdoor functionality that enables remote control and credential theft.

The campaign, which researchers say has been active since at least February 2026, is designed to steal cryptocurrency by silently replacing wallet addresses and harvesting sensitive credentials from infected devices.

USB Infection Method Enables Rapid Spread

According to Microsoft’s threat intelligence team, the malware propagates by scanning removable storage devices and replacing legitimate documents with malicious Windows shortcut (.lnk) files.

The technique targets commonly used file formats, including Word, Excel and PDF documents. Original files are hidden from view while attackers create lookalike shortcuts using identical filenames, increasing the likelihood that users unknowingly execute the malware.

Once activated, the malware establishes persistence on the infected system and automatically spreads to additional USB drives connected to the device, creating a worm-like distribution mechanism capable of moving between networks without relying on internet-based delivery.

Clipboard Hijacking Targets Crypto Transactions

The campaign’s primary objective is cryptocurrency theft.

Researchers found that the malware continuously monitors clipboard activity, checking copied content roughly every half second for patterns associated with cryptocurrency wallet addresses.

When a user copies a wallet destination before making a transaction, the malware silently substitutes the address with one controlled by the attacker. Because crypto transfers are irreversible, victims may unknowingly send funds directly to malicious wallets.

Microsoft’s analysis indicates the malware is configured to recognize addresses associated with multiple blockchain networks, including Bitcoin, Ethereum, Monero and Tron.

The attack method reflects a broader trend among cybercriminals targeting operational mistakes rather than attempting to compromise blockchain protocols directly.

Beyond a Clipper: Malware Includes Full Backdoor Functionality

Researchers noted that the threat extends beyond a traditional cryptocurrency clipper.

The malware deploys a lightweight backdoor that enables attackers to maintain persistent access to infected systems. To conceal communications, it bundles its own Tor client, allowing traffic to be routed through anonymous hidden services.

The infrastructure enables operators to exfiltrate private keys, seed phrases and other sensitive wallet information while also receiving screenshots and system intelligence from compromised devices.

The functionality gives attackers the ability to update payloads, deliver additional malware and adapt operations without requiring physical access to infected machines.

Advanced Evasion Techniques Complicate Detection

Microsoft reported that the malware incorporates several mechanisms designed to evade security analysis.

Core components remain encrypted until execution, limiting visibility for traditional scanning tools. The malware also performs anti-analysis checks and may terminate itself if system monitoring tools are detected.

Persistence mechanisms include scheduled tasks that automatically relaunch malicious processes after reboots, ensuring continued operation even after partial remediation attempts.

The combination of obfuscation, persistence and anonymous command-and-control infrastructure demonstrates a level of sophistication increasingly common among financially motivated cybercrime groups.

Crypto Holders Face Growing Operational Security Risks

The discovery comes as digital asset adoption continues to expand among retail and institutional investors, increasing the potential attack surface for threat actors.

Unlike exploits targeting blockchain protocols, clipboard hijacking attacks rely on user behavior and transaction workflows, making them difficult to detect without strong operational security practices.

Security researchers note that even experienced users can become victims if wallet addresses are not manually verified before transaction confirmation.

The campaign also highlights the continued relevance of removable media as an attack vector despite the growing shift toward cloud-based infrastructure.

Microsoft Recommends Immediate Defensive Measures

Microsoft advises organizations and individual users to disable AutoRun and AutoPlay functionality for removable media, restrict execution of shortcut files from USB devices and limit access to Windows scripting tools where operationally possible.

Security teams are also encouraged to monitor systems for unusual Tor-related network activity, which may indicate active communication with attacker-controlled infrastructure.

For cryptocurrency users, experts recommend verifying wallet addresses before every transaction, using hardware wallets where possible and maintaining strict controls around removable storage devices.

The campaign serves as a reminder that while blockchain networks themselves may remain secure, the endpoints used to access digital assets continue to represent one of the industry’s most significant security vulnerabilities.


Credit: Source link

Previous ArticleOpen USD, Ripple RLUSD and the XRP Bull Case
Next Article Robinhood Expands AI Trading Tools to Crypto With Agentic Platform

Related Posts

H100’s BTC Stash Soars as Empery Digital Dumps Bitcoin

August 10, 2026

Cardano Opens 2.5 Million ADA Funding Round for New Projects

August 10, 2026

No OFAC Listing For ‘Shelbit’ Or ‘Aban Tether’

August 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

BNB price breaks $600, can bulls trigger a rally to $635?

August 10, 2026

H100’s BTC Stash Soars as Empery Digital Dumps Bitcoin

August 10, 2026

Cardano Opens 2.5 Million ADA Funding Round for New Projects

August 10, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

CLARITY Act Leaves 5 Loopholes, From Pensions to Trump’s $1.4B Crypto

Prediction Markets Explode, Circle Has Hot Q2, and More

Bitcoin BIP-110 split widens as fork freezes at 2 blocks

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$64,701.000.00%
  • ethereumEthereum(ETH)$1,901.80-0.50%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$601.31-0.10%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.03-0.70%
  • solanaSolana(SOL)$76.450.30%
  • tronTRON(TRX)$0.3312520.50%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.000.10%
  • HyperliquidHyperliquid(HYPE)$54.711.10%
  • dogecoinDogecoin(DOGE)$0.069716-0.40%
  • USDSUSDS(USDS)$1.000.00%
  • RainRain(RAIN)$0.012533-0.60%
  • leo-tokenLEO Token(LEO)$9.65-0.80%
  • zcashZcash(ZEC)$505.03-3.80%
  • moneroMonero(XMR)$394.174.50%
  • cardanoCardano(ADA)$0.195929-0.10%
  • whitebitWhiteBIT Coin(WBT)$55.90-0.20%
  • chainlinkChainlink(LINK)$8.28-0.10%
  • stellarStellar(XLM)$0.1628300.20%
  • daiDai(DAI)$1.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$214.76-0.40%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • CantonCanton(CC)$0.0995332.10%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.34-0.80%
  • litecoinLitecoin(LTC)$45.41-1.80%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • hedera-hashgraphHedera(HBAR)$0.068392-0.80%
  • suiSui(SUI)$0.690.20%
  • avalanche-2Avalanche(AVAX)$6.531.10%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • shiba-inuShiba Inu(SHIB)$0.0000051.30%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,314.67-0.50%
  • uniswapUniswap(UNI)$4.000.50%
  • crypto-com-chainCronos(CRO)$0.047421-3.00%
  • nearNEAR Protocol(NEAR)$1.662.60%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.140.00%
  • okbOKB(OKB)$93.900.40%
  • BittensorBittensor(TAO)$203.60-1.60%
  • pax-goldPAX Gold(PAXG)$4,329.47-0.50%
  • OndoOndo(ONDO)$0.3489890.60%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0531252.90%
  • AsterAster(ASTER)$0.611.00%
  • HTX DAOHTX DAO(HTX)$0.0000020.80%
  • usddUSDD(USDD)$1.000.00%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • MemeCoreMemeCore(M)$1.10-3.60%