Skip to main content
AVOID.NET

Crypto Clipper Worm (Microsoft DCU Takedown June 2026)

avoid.net/crypto-clipper-worm-microsoft-dcu-takedown-june-2026→0/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·JztKWD…44xZ

Summary

CryptoBandits is a self-propagating Windows malware campaign active since February 2026 that combines clipboard hijacking, seed-phrase theft, wallet-address substitution, and worm-like USB propagation with Tor-based command-and-control infrastructure. Microsoft Threat Intelligence disclosed the campaign on June 17, 2026, under the Defender detection name Trojan:Win32/CryptoBandits. Microsoft's Digital Crimes Unit, acting alongside Europol and law enforcement from multiple countries as part of Operation Endgame, disrupted the broader StealC and Amadey botnet infrastructure that delivered related infostealers on June 24, 2026, seizing 182 C2 IP addresses across 47 domains and freezing approximately EUR 41 million in criminal cryptocurrency assets.

Connected Entities

4 entities · 60 linked investigations
Organizations
□Crypto Clipper Worm (Microsoft DCU Takedown June 2026)□Ethereum64□Monero58
Tokens
Relationships
  • Crypto Clipper Worm (Microsoft DCU Takedown June 2026)→mentioned with→Ethereum(60%)
  • Crypto Clipper Worm (Microsoft DCU Takedown June 2026)→mentioned with→Bitcoin(75%)
  • Crypto Clipper Worm (Microsoft DCU Takedown June 2026)→mentioned with→Monero(60%)
  • Ethereum→mentioned with→Bitcoin(60%)
  • Monero→mentioned with→Bitcoin(60%)
Have evidence about Crypto Clipper Worm (Microsoft DCU Takedown June 2026)?

Timeline(6 events)

February 2026

Microsoft Defender Experts begin tracking the CryptoBandits cryptocurrency clipper campaign. The malware is observed spreading via malicious USB .lnk shortcut files with Tor-based C2 communications.

Microsoft Security Blog

May 2026

Amadey botnet linked to over 140,000 infected computers worldwide during the first two weeks of May 2026, according to Operation Endgame figures. BitSight TRACE analyzes over 200,000 Amadey infections over a 90-day window.

Europol / Help Net Security

17 June 2026

Microsoft Threat Intelligence and Microsoft Defender Experts publicly disclose the CryptoBandits campaign in a detailed security blog post, documenting USB LNK propagation, Tor C2, seed phrase theft, wallet address substitution, and backdoor capabilities.

Microsoft Security Blog

18 June 2026

Operation Endgame disrupts SocGholish malware infrastructure in an earlier phase of the coordinated law enforcement sweep.

Help Net Security

19 June 2026

CoinDesk, The Next Web, and multiple crypto-security outlets publish coverage of the CryptoBandits disclosure, broadening awareness of the USB worm campaign.

CoinDesk

24 June 2026

Microsoft's Digital Crimes Unit and Europol, in coordination with law enforcement from Canada, Denmark, Germany, the Netherlands, the United Kingdom, and the United States, announce Operation Endgame disruption of StealC and Amadey infrastructure: 326 servers and 142 domains actioned; 182 C2 IP addresses seized across 47 domains; 18,000+ victim computers severed from criminal control; approximately 27 million stolen credentials recovered; EUR 41 million in cryptocurrency assets frozen. Microsoft files civil lawsuits against alleged operators and affiliates.

Europol / Microsoft Security Blog
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 19 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 6/26/2026, 12:17:24 PM

last updated: 7/27/2026, 10:56:29 AM

5 views

avoid.net — verified advice for a post-truth world