logo

Proxyware Malware Mimic as YouTube Video Download Site Delivers Malicious Javascripts

ID: 1727aeb6-f475-5edb-b01c-9bf95eef9943

STIX ID: report--1727aeb6-f475-5edb-b01c-9bf95eef9943

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-08-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers observed a surge of deceptive YouTube video download sites delivering a multi-stage Proxyware campaign that lures victims to download a fake utility (WinMemoryCleaner). The installer drops an executable and a PowerShell updater that installs Node.js, fetches a malicious JavaScript loader (pas.js) from CloudFront, and registers scheduled tasks (“Schedule Update” and “WindowsDeviceUpdates”) to run the JavaScript under Node.js; the final payload deploys Proxyware (DigitalPulse/HoneyGain/Infatica) to steal and monetize victims’ network bandwidth, causing degraded network performance and evading sandbox analysis. The report includes filenames, URLs, and task names as IOCs and notes the attacker’s use of legitimate hosting (GitHub/CloudFront) and affiliate monetization to scale operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.