Skip to main content
Sign in

Crypto Clipper Worm (Microsoft DCU Takedown June 2026)

avoid.net/crypto-clipper-worm-microsoft-dcu-takedown-june-20260/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·JztKWD…44xZ

Summary

CryptoBandits is a self-propagating Windows malware campaign active since February 2026 that combines clipboard hijacking, seed-phrase theft, wallet-address substitution, and worm-like USB propagation with Tor-based command-and-control infrastructure. Microsoft Threat Intelligence disclosed the campaign on June 17, 2026, under the Defender detection name Trojan:Win32/CryptoBandits. Microsoft's Digital Crimes Unit, acting alongside Europol and law enforcement from multiple countries as part of Operation Endgame, disrupted the broader StealC and Amadey botnet infrastructure that delivered related infostealers on June 24, 2026, seizing 182 C2 IP addresses across 47 domains and freezing approximately EUR 41 million in criminal cryptocurrency assets.

Connected Entities

1 entities · 10 linked investigations
Organizations
Crypto Clipper Worm (Microsoft DCU Takedown June 2026)
Relationships
    Have evidence about Crypto Clipper Worm (Microsoft DCU Takedown June 2026)?

    Timeline(6 events)

    2026-02-01

    Microsoft Defender Experts begin tracking the CryptoBandits cryptocurrency clipper campaign. The malware is observed spreading via malicious USB .lnk shortcut files with Tor-based C2 communications.

    Microsoft Security Blog

    2026-05-01

    Amadey botnet linked to over 140,000 infected computers worldwide during the first two weeks of May 2026, according to Operation Endgame figures. BitSight TRACE analyzes over 200,000 Amadey infections over a 90-day window.

    Europol / Help Net Security

    2026-06-17

    Microsoft Threat Intelligence and Microsoft Defender Experts publicly disclose the CryptoBandits campaign in a detailed security blog post, documenting USB LNK propagation, Tor C2, seed phrase theft, wallet address substitution, and backdoor capabilities.

    Microsoft Security Blog

    2026-06-18

    Operation Endgame disrupts SocGholish malware infrastructure in an earlier phase of the coordinated law enforcement sweep.

    Help Net Security

    2026-06-19

    CoinDesk, The Next Web, and multiple crypto-security outlets publish coverage of the CryptoBandits disclosure, broadening awareness of the USB worm campaign.

    CoinDesk

    2026-06-24

    Microsoft's Digital Crimes Unit and Europol, in coordination with law enforcement from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, announce Operation Endgame disruption of StealC and Amadey infrastructure: 326 servers and 142 domains actioned; 182 C2 IP addresses seized across 47 domains; 18,000+ victim computers severed from criminal control; approximately 27 million stolen credentials recovered; EUR 41 million in cryptocurrency assets frozen. Microsoft files civil lawsuits against alleged operators and affiliates.

    Europol / Microsoft Security Blog
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

    model: claude-code-investigator

    generated: 6/26/2026, 12:17:24 PM

    last updated: 6/26/2026, 12:17:33 PM

    avoid.net — verified advice for a post-truth world