Loading prices…
〽️NEUTRAL

CryptoBandits Malware Hides in 8 Steam Games, Warns Microsoft

The campaign weaponises USB shortcuts, clipboard monitoring, and Tor to drain wallets, with an Uber Eats delivery breadcrumb hinting at how far the operators are willing to mass-pollute endpoints.

Microsoft's threat intelligence team has flagged CryptoBandits, a malware family packaged inside at least eight Steam games, that turns an infected machine into a pivot for wallet theft. The lure targets the usual Steam footprint, but the payload targets the wallet footprint sitting next to it.

How the chain works

CryptoBandits drops USB shortcut files (.lnk) that masquerade as legitimate drives. Once a victim plugs in a USB stick, the malware reaches outward through the shortcut, hijacks clipboard activity to rewrite wallet addresses mid-paste, and routes outbound traffic over Tor to avoid attribution. The final hop exfiltrates tokens and seed phrases from browser and desktop wallet workflows before funds move.

Why it matters

Microsoft's research team, including Liam "Akiba" Wright, linked one command-and-control fingerprint to a string of suspicious Uber Eats delivery confirmations in victim inboxes, suggesting the operators are testing infrastructure at consumer scale before committing it to higher-value targets. The combination of mass-distribution games, USB-resident propagation, and clipboard swap puts the campaign firmly in the category of broad-spectrum stealer malware rather than a targeted operation.

Frequently asked questions

  1. What is CryptoBandits malware?

    CryptoBandits is a malware family Microsoft flagged inside at least eight Steam games. It drops fake USB shortcut files, monitors the clipboard to rewrite wallet addresses, and uses Tor to exfiltrate tokens and seed phrases.

  2. How does CryptoBandits steal crypto?

    It plants malicious .lnk files that activate when a victim plugs in a USB drive, then hijacks clipboard activity to swap pasted wallet addresses mid-transaction. Outbound traffic is routed through Tor to obscure attribution before funds move.

  3. Why is Microsoft linking the campaign to Uber Eats?

    Researcher Liam "Akiba" Wright's team found that one command-and-control fingerprint appeared alongside suspicious Uber Eats delivery confirmations in victim inboxes, suggesting operators were stress-testing infrastructure at consumer scale.

  4. Which wallets and platforms are at risk?

    Microsoft's write-up targets browser-based and desktop wallet workflows, including seed-phrase stores on infected machines. Any wallet whose address passes through the clipboard during a transaction is exposed to the swap.

  5. How can users protect themselves from clipboard-swapping stealers?

    Verify wallet addresses character by character before confirming, keep seed phrases off internet-connected machines, treat unknown USB devices as hostile, and avoid running unsigned or pirated software, including unvetted Steam titles.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 15h ago
Open original →