Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems
ID: a6ee6d2e-aeba-52bd-80d6-bd068c105991
STIX ID: report--a6ee6d2e-aeba-52bd-80d6-bd068c105991
Feed Name: cybersecurityNews.com
Threat Score
A malicious campaign attributed to Larva-25012 distributes proxyware hidden inside fake Notepad++ installers (MSI and ZIP) on fraudulent download portals, primarily targeting users in South Korea; the malware uses DLL side-loading, process injection, Task Scheduler persistence, and installs Infatica/DigitalPulse proxy modules to hijack victims' network bandwidth for profit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
