Microsoft Warns of Malware Stealing Crypto Wallets Through USB Drives
Microsoft found malware that infects Windows PCs through USB drives and replaces crypto wallet addresses in the clipboard. Here’s how the attack works and why crypto users should be especially alert.

Key Takeaways
- Microsoft found malware that spreads through infected USB drives and tries to steal crypto wallets.
- The malware uses a malicious .lnk file, installs a worm, and replaces wallet addresses in the Windows clipboard.
- Microsoft published indicators of compromise to help spot infections and warns people to be careful when using USB drives.
Microsoft has found a new piece of malware that spreads through USB drives and has been infecting Windows PCs since February, with the goal of hijacking crypto wallets. This malware, which Microsoft calls a "crypto clipper" and identifies as Trojan:Win32/CryptoBandits, works through a malicious shortcut file (.lnk) on an infected USB drive.
How the Malware Works
When a user plugs in an infected USB drive and opens the shortcut file, a worm gets installed on the PC. That worm keeps running code aimed at stealing crypto wallet information. At the same time, the worm waits for a new, clean USB drive to be plugged in so it can spread there too. The malware intercepts data from the Windows clipboard and swaps out stored wallet addresses with the attackers' addresses, which can send transfers to the wrong wallets.
Risks and Security Measures
Clipper malware has been a known threat in the crypto world since 2017 and is estimated to have stolen about $400,000 (€349,000) worth of cryptocurrencies in 2023. The mix of USB drives as a spread method and clipboard tampering makes this malware especially dangerous and hard to detect. Microsoft has published a list of indicators of compromise, including file hashes and command-and-control servers, to help security teams spot infections.
Why This Matters for European Crypto Users
For users in Europe, this discovery highlights how important it is to stay alert when using USB drives and to double-check wallet addresses before making transactions. The growing sophistication of malware that specifically targets crypto wallets shows why good security habits and keeping antivirus software up to date matter so much for avoiding financial losses. Crypto security is often about more than just code flaws, it also comes down to human and operational risk; that is also clear from the broader trend described in crypto security requires more than just audits to prevent losses.