Mark RadarMARK RADAR
EN
Event File CRYPTO Cryptocurrency Wallets

Microsoft Warns USB-Spreading Crypto Clipper Malware Is Hijacking Wallet Transfers

4 reports · First detected 2026-06-19 · Last active 2026-06-23

Microsoft Threat Intelligence said cryptocurrency clipper malware is exploiting the Windows clipboard. Because users typically copy and paste wallet addresses, the malware can secretly replace the intended recipient address and divert assets to an attacker’s wallet. The number of victims and the amount stolen have not been disclosed.

The malware has remained active since February and was recently found to spread through USB drives, creating a cross-device infection chain. In addition to altering cryptocurrency wallet addresses stored in the clipboard, it can capture screenshots to steal credentials and serve as a backdoor for executing arbitrary code. Related activity was also covered in a June 23 cybersecurity daily report.

All Coverage

4 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)