Microsoft · CryptoSlate
Microsoft said initial access occurs through malicious.lnk files, including shortcuts distributed on USB storage devices
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
The malware then scans the USB drive for common document files, such as.doc,.xlsx, and.pdf, hides the originals, and creates new shortcut files with the same file names.
Key facts
- It searches for 12- or 24-word BIP39 seed phrases, Bitcoin WIF keys, Ethereum keys, and cryptocurrency addresses
- In a June 17 Security Blog report, Microsoft said the CryptoBandits malware, detected as “CryptoBandits
- A”, had been active since February 2026 and has reached systems through malicious Windows shortcut files on USB storage devices
- It also called out local SOCKS5 proxy activity on localhost:9050, clipboard-related behavior, and PowerShell screen-capture activity on devices that handle sensitive financial workflows
Summary
01 Microsoft says CryptoBandits. 02 The malware polls the clipboard for seed phrases and addresses, so a compromised endpoint can alter or expose wallet data. 03 Microsoft did not disclose theft totals or attribution, leaving the scale of damage and victim exposure unclear. Microsoft’s latest crypto malware research points to crypto wallets, one of several places a transaction can fail, as a key practical weakness in self-custody,. A compromised Windows machine can change the address a user copies, expose a seed phrase before a transfer is signed, or send screenshots and wallet context back to an attacker.