Disclaimer:All content on this platform is sourced from the internet and is provided for informational purposes only. None of the content represents the views of this site, nor does it constitute investment advice. Please exercise caution when investing.
Microsoft New Encrypting Trojan Threat Revealed: Can Spread Covertly via Tor and Hijack Wallet Addresses
Svmuu News Microsoft The company’s threat intelligence team has officially disclosed a Windows encryption Trojan threat that has been active since February 2026. This malware combines “worm-like propagation, clipboard hijacking, and Tor-based anonymous communication” to target users of digital assets. Microsoft Analysis indicates that the malware spreads between removable storage devices via disguised shortcut (.lnk) files. It uses WScript and ActiveX to execute script logic, automatically deploys a local Tor client, and connects via a proxy at 127.0.0.1:9050.It uses an onion hidden service C2 server to enable anonymous control and data transmission.The attack chain includes multiple malicious capabilities: continuously monitoring clipboard content, stealing mnemonic phrases and private keys, taking and uploading screenshots, and performing “address replacement” when the user copies a cryptocurrency address—replacing the target address with a wallet address controlled by the attacker to hijack funds. Additionally, this Trojan possesses worm-like propagation capabilities, automatically replicating itself onto devices such as USB drives and creating scheduled tasks to ensure persistent operation. It also features basic anti-analysis capabilities (such as monitoring the Task Manager to evade debugging). In terms of detection, Microsoft has identified it as part of the Trojan:Win32/CryptoBandits family and blocks it based on behavioral signatures (such as abnormal WScript calls, localhost:9050 proxy traffic, and PowerShell screenshot activities). Security researchers recommend prioritizing protection of script execution paths and monitoring for abnormal local proxy traffic.
Disclaimer: This content reflects the author's personal views only and does not constitute investment advice. If you find any violations, please Click to Report
24H Trending
-
Iranian Foreign Ministry: Iran and the U.S. Reach Agreement
-
Binance Seven U-denominated perpetual contracts, including LRCX and KLAC, will be launched
-
Gate's Stock Contracts Section Launches Trading for 8 Perpetual Contracts, Including ADSK (Autodesk) and BKNG (Booking.com Holdings)
-
Learn More About the ALTHEA Token (ALTH) and Its Decentralized Network
-
Morgan Stanley Updates Ethereum and Solana ETF Filings, Proposing a 0.14% Fee
-
The OKX DEX xStocks Trading Competition is currently underway, with a total prize pool of 300,000 USDC
-
After going long on crude oil with 10x leverage, the position is showing a paper loss of $1.33 million; a certain address holds CL long positions worth $37.77 million
-
Iranian media report that Iran-U.S. negotiations have resulted in five key points
-
Mainland China’s Dogecoin Trading Platform: Current Status—Regulatory Policies and Global Mainstream Options
-
Record-High AI-Driven Leveraged Bets in Asia: SK Hynix’s 2x Long ETF in South Korea Reaches $13 Billion in Assets Under Management
Recommended Reading





