Researchers detailed two Windows malware strains that spread through removable media and target cryptocurrency users. Microsoft-tracked Trojan:Win32/CryptoBandits.A uses malicious .LNK shortcut files on USB drives to hide legitimate documents, replace them with look-alike shortcuts, and copy itself to newly attached media. Once launched, it steals seed phrases and private keys, captures screenshots, replaces copied wallet addresses with attacker-controlled values, and uses a bundled Tor client over localhost:9050 for command-and-control; an EVAL backdoor command also enables arbitrary code execution on infected hosts.
Separate reverse-engineering of a Phorpiex sample showed similar USB and network-drive worm behavior alongside downloader and crypto-theft functions. The malware copies itself to writable locations for persistence, creates a Run key named Windows Settings, deletes its Zone.Identifier alternate data stream, adds Windows Defender exclusions, and disables Windows Update- and Defender-related protections. It also spreads as VolDrvConfig.exe, performs clipboard hijacking to redirect cryptocurrency payments, and downloads additional payloads, including cryptominers, from hard-coded infrastructure such as 185.215.113.66 into the temp directory under randomized filenames.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence identified an active Windows malware campaign tracked as Trojan:Win32/CryptoBandits.A that has been affecting users since at least February 2026. The malware spreads through malicious .LNK shortcut files on USB drives and steals cryptocurrency-related data while maintaining Tor-based command-and-control access.
A reverse-engineering write-up documented a Phorpiex Windows worm sample that spreads via USB and network drives, establishes persistence, weakens Windows defenses, performs crypto-clipping, and downloads additional payloads from hard-coded infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.