Microsoft says CryptoBandits Windows malware steals cryptocurrency and uses Tor as a backdoor

Microsoft says a Windows malware family called CryptoBandits is infecting systems and stealing cryptocurrency by swapping copied wallet addresses, while also giving attackers remote access. The campaign has been active since February 2026 and spreads through malicious .lnk shortcut files and infected USB devices. It drops a portable Tor client, uses a local SOCKS5 proxy for hidden command-and-control traffic, achieves persistence with scheduled tasks, and can steal seed phrases, private keys, clipboard data, and screenshots while receiving follow-on commands.
Why it matters: This matters to both consumers and organizations because an infection can silently redirect crypto payments and provide attackers with ongoing access to a Windows device. Defenders should watch for suspicious .lnk files, USB-based propagation, unexpected local SOCKS5/Tor activity, and script execution via Windows Script Host, while users should avoid opening untrusted shortcut files and verify wallet addresses before sending funds.

Sources

CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
Ionut Arghire 2026.06.19 100% relevant
This article appears to be the first tracked item establishing the CryptoBandits malware campaign as a distinct story, with Microsoft providing the core technical analysis and attack details.
← Back to all stories