Microsoft security researchers found that a malicious software campaign targeting encryption users was expanding. These horses were named Crypto Clipper, which Microsoft described as the earliest date to February 2026. Unlike common clipboard hijacking procedures, this version also has the ability to steal sensitive information, screens and remote enforcement codes.

Stealable notes and private keys

According to Microsoft, Crypto Clipper continuously monitors the clipboard of victim equipment for high-value encryption data. Objectives include 12 words and 24 word assistive words, private keys to the Taifung, and bitcoin wallet vouchers.

Once the content is identified, the horse will pass the data out through a command and control infrastructure based on Tor. It also intercepts the device screens and helps the attackers learn more about wallet interfaces, account balances, etc.

Replaceable transfer address

Another key capability of the attack was to replace the user with a copy of the wallet address. Microsoft indicated that the horse would check the address in the clipboard and change it to a similar address under the control of the assailant in order to reduce the probability that the user would detect anomalies in the transfer.

  • Confirmed involving bitcoin network
  • It's also a "Tron" address.
  • It also covers Monero.

This means that once the user has not carefully checked the receipt address, the asset may be transferred to the attackers ' wallet.

Maintain long-term control through Tor

Microsoft also noted that the manner in which the event was disseminated was of concern. The researchers found that the horse would deploy a portable Tor client and communicate with the attackers through hidden services.

On this basis, the attackers not only steal the clipboard contents but also issue further instructions to the infected equipment, including the enforcement of any code. According to Microsoft, after a combination of clipboard thefts, screens, Tor communications and remote mission control, the attackers were able to quickly realize and maintain control over the equipment that had been invaded.

Additional information:According to Microsoft, this type of horse is not only involved in the transfer chain, but also directly collects assistive notes and private keys and, once the information is leaked, the assailant can access the wallet directly by bypassing the original device.