Researchers detailed two Windows malware strains that spread through removable media and target cryptocurrency users. Microsoft-tracked Trojan:Win32/CryptoBandits.A uses malicious .LNK shortcut files on USB drives to hide legitimate documents, replace them with look-alike shortcuts, and copy itself to newly attached media. Once launched, it steals seed phrases and private keys, captures screenshots, replaces copied wallet addresses with attacker-controlled values, and uses a bundled Tor client over localhost:9050 for command-and-control; an EVAL backdoor command also enables arbitrary code execution on infected hosts.
Separate reverse-engineering of a Phorpiex sample showed similar USB and network-drive worm behavior alongside downloader and crypto-theft functions. The malware copies itself to writable locations for persistence, creates a Run key named Windows Settings, deletes its Zone.Identifier alternate data stream, adds Windows Defender exclusions, and disables Windows Update- and Defender-related protections. It also spreads as VolDrvConfig.exe, performs clipboard hijacking to redirect cryptocurrency payments, and downloads additional payloads, including cryptominers, from hard-coded infrastructure such as 185.215.113.66 into the temp directory under randomized filenames.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence identified an active Windows malware campaign tracked as Trojan:Win32/CryptoBandits.A that has been affecting users since at least February 2026. The malware spreads through malicious .LNK shortcut files on USB drives and steals cryptocurrency-related data while maintaining Tor-based command-and-control access.
A reverse-engineering write-up documented a Phorpiex Windows worm sample that spreads via USB and network drives, establishes persistence, weakens Windows defenses, performs crypto-clipping, and downloads additional payloads from hard-coded infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.