Microsoft tracks Windows “CryptoBandits” clipper stealing seed phrases and keys via Tor and infected USB drives
Microsoft Threat Intelligence has been tracking a Windows cryptocurrency clipper it calls CryptoBandits. The activity has been ongoing since February 2026.