EPISODE · Jun 19, 2026 · 0 MIN
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
from Security Stuff · host Trace3
Microsoft has identified a sophisticated Windows malware called CryptoBandits that functions as both a cryptocurrency clipper and a lightweight backdoor, routing traffic through a built-in Tor client and local SOCKS5 proxy to avoid detection. The malware spreads via malicious shortcut files, propagates through USB devices, and continuously polls its command-and-control server every 500 milliseconds to steal crypto wallet information and replace clipboard addresses with attacker-controlled ones. Microsoft recommends organizations harden script execution paths and monitor for SOCKS proxy abuse, as this threat demonstrates how lightweight script-based malware can deliver significant damage when combined with anonymized communications.
Embed this episode
What this episode covers
Microsoft has identified a sophisticated Windows malware called CryptoBandits that functions as both a cryptocurrency clipper and a lightweight backdoor, routing traffic through a built-in Tor client and local SOCKS5 proxy to avoid detection. The malware spreads via malicious shortcut files, propagates through USB devices, and continuously polls its command-and-control server every 500 milliseconds to steal crypto wallet information and replace clipboard addresses with attacker-controlled one...
NOW PLAYING
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.