Microsoft found crypto-stealing malware on USB drives. Your copied wallet address is the target.
CryptoBandits doesn't need you to approve a transaction. It waits for a copied address, swaps it, then moves the real theft over Tor.

CryptoVibe Desk · security · malware · microsoft

- →Microsoft disclosed CryptoBandits, a USB-spreading Windows malware campaign active since at least February 2026, per CoinDesk.
- →The malware checks copied wallet addresses every 500 milliseconds and swaps them with attacker-controlled addresses.
- →Watch for confirmed victim counts or wallet losses within 30 days, because none were disclosed today.
- Wallet address → A wallet address is the public string you paste when sending crypto to someone.
- Seed phrase → A seed phrase is the backup phrase that can restore and control a crypto wallet.
- Tor → Tor is a privacy network attackers can use to hide where stolen data is being sent.
CryptoBandits checks copied wallet addresses every 500 milliseconds.
Microsoft disclosed the Windows malware campaign today, per CoinDesk, dating it to at least February 2026. The company identifies it as Trojan:Win32/CryptoBandits.
The trick is simple. When a user copies a crypto wallet address, the malware swaps it with an attacker-controlled address. If you're sending funds in a hurry, your bag can move before you notice the pasted address changed.
The USB part makes this worse. Microsoft says the worm spreads by replacing normal documents on clean USB drives with malicious .lnk shortcut files. The files keep the same names, which makes the trap look boring. That's the catch.
The malware also goes after seed phrases and private keys. CoinDesk reports it captures 5 screenshots, 10 seconds apart, during credential theft. It then sends stolen data through Tor, with the local proxy using port 9050, according to the report.
Microsoft published file hashes and .onion command-and-control domains. It also told users to disable AutoRun, block .lnk execution on USB media, and restrict Windows script hosts.
No victim count, dollar loss, or country split was disclosed today. The number to watch is not price. It is whether this stays a malware bulletin or turns into named wallet losses.
Wallet apps hardened the signing screen and left the clipboard unguarded. CryptoBandits is the cost of that gap.
Before July 19, watch for Microsoft or major wallet teams to confirm victim counts, stolen wallet clusters, or blocked CryptoBandits addresses.
Primary links and supporting reads used by the desk for this story.
Forward this.











