CryptoBandits is a Windows-based cryptocurrency clipper and stealer malware family, tracked by Microsoft as Trojan:Win32/CryptoBandits.A, that has been active since at least February 2026. It spreads via malicious Windows shortcut (.LNK) files on USB/removable drives. The worm component hides legitimate documents such as DOC, XLSX, and PDF files, replaces them with look-alike malicious shortcuts using the same names and icons, and propagates to newly connected removable media. It establishes persistence via scheduled tasks and has been reported to add Microsoft Defender exclusions for staging folders and related binaries.
Its primary theft behavior is clipboard hijacking: it monitors the clipboard roughly every 500 milliseconds for cryptocurrency wallet addresses, 12- or 24-word BIP39 seed phrases, Ethereum private keys, and Bitcoin WIF keys. When wallet addresses are copied, it replaces them with attacker-controlled addresses, including for Bitcoin legacy, P2SH, Bech32, Taproot, Tron, and Monero formats. It also captures screenshots, commonly five over a ten-second interval, for exfiltration.
CryptoBandits uses Windows Script Host components such as wscript.exe and cscript.exe, along with PowerShell, cmd.exe, ActiveX/WScript logic, curl, and a bundled portable Tor client renamed ugate.exe. It routes command-and-control traffic through a local SOCKS5 proxy on 127.0.0.1:9050 and communicates with Tor hidden-service (.onion) infrastructure, including use of /route.php for check-ins and command retrieval, /recvf.php for file uploads, and /stub.php for payload downloads. The malware includes backdoor functionality via an EVAL command that enables arbitrary code execution by downloading JavaScript into a local file named cfile and executing it, effectively making it a lightweight backdoor in addition to a crypto-stealer.
The malware uses layered obfuscation, including a Python-based installer obfuscated with PyArmor and packaged with PyInstaller, plus obfuscated JavaScript payloads stored under C:\Users\Public\Documents. It performs a simple anti-analysis check by detecting Task Manager and exiting if taskmgr.exe is running. Microsoft Defender Antivirus and Defender for Endpoint detect related activity under names including Trojan:Win32/CryptoBandits.A, Trojan:Win32/CryptoBandits.B, Trojan:JS/CryptoBandits.A, and Trojan:JS/CryptoBandits.B. Reported indicators include SHA-256 hashes 7630debd35cac6b7d58c4427695579b3e3a8b1cc462f523234cd6c698882a68c and a7abf1d9d6686af1cefcd60b17a312e7eb8cfe267def1ec34aeab6128c811630, and .onion C2 domains such as cgky6bn6ux5wvlybtmm3z255igt52ljml2ngnc5qp3cnw5jlglamisad.onion and gfoqsewps57xcyxoedle2gd53o6jne6y5nq5eh25muksqwzutzq7b3ad.onion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
It then drops its main files ... and finally sets up automatic background tasks to keep running and infect any new USB drives plugged into the computer.
An EVAL command from the server runs new code hidden in a local file named cfile, granting attackers permanent remote control.
Malicious .LNK files execute hidden commands through wscript.exe and cscript.exe (Windows Script Host) to install the malware without user awareness.
The malware employs multiple layers of evasion: PyArmor obfuscation... Dual-layer JavaScript obfuscation... All malware components are encrypted and only decrypted at runtime.
Перед запуском он проверяет список активных процессов и завершает работу, если обнаруживает диспетчер задач.
Task Manager detection: The malware checks whether Task Manager is running and exits if it detects the process, frustrating casual investigation.
Malware extracts BIP39 seed phrases, Ethereum private keys, Bitcoin WIF keys, and captures five screenshots over ten seconds for exfiltration to the C2 server.
The central component of the threat is the bundled Tor client, which routes communication over localhost:9050 and resolves destination domains to reduce DNS visibility and hide its C&C location.
регистрирует жертву на управляющем сервере и начинает постоянный обмен командами через локальный SOCKS5-прокси.
Dubbed CryptoBandits, the malware has been used in attacks since February 2026, deploying a portable Tor client on the infected systems and routing traffic through a local SOCKS5 proxy.
The malware bundles a portable Tor client (ugate.exe) and routes all traffic through a SOCKS5 proxy on localhost:9050 to a hidden .onion service.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-based cryptocurrency clipper active since February 2026 that spreads via malicious USB .lnk shortcuts, hides files, sets Windows Defender exclusions, monitors the clipboard for cryptocurrency wallet addresses, private keys, and seed phrases, swaps copied wallet addresses with attacker-controlled ones, captures screenshots, communicates over a bundled Tor client, and can execute server-supplied code for persistent remote control.
Referenced only by title as malware that doubles as a backdoor and abuses Tor.
Windows malware active since at least February 2026 that spreads via USB drives using malicious LNK files. It steals cryptocurrency-related data by monitoring the clipboard, harvesting BIP39 seed phrases and private keys, replacing wallet addresses, taking screenshots, and communicating with operators over Tor hidden services. It also behaves like a worm by copying itself to new USB devices and supports remote code execution via attacker-supplied JavaScript.
A USB-propagating Windows worm that spreads via malicious .LNK shortcut files, hides legitimate documents, replaces them with look-alike shortcuts, hijacks cryptocurrency clipboard data, steals seed phrases and private keys, captures screenshots, and communicates with C2 over a bundled Tor client. It also supports arbitrary code execution via EVAL, functioning as a lightweight backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.