Microsoft detailed an active malware campaign called CryptoBandits that spreads through infected USB drives, silently replaces crypto wallet addresses in your clipboard every 500 milliseconds, and routes stolen data through a bundled Tor client to evade detection. Active since February 2026 and targeting Bitcoin, Tron, and Monero, the campaign is a reminder that physical attack surfaces are still the most underdefended part of most crypto security setups.






