Fake Proxifier GitHub Installer Spreads ClipBanker Crypto Malware
ID: 383f6284-d479-5786-8082-6db7d105881f
STIX ID: report--383f6284-d479-5786-8082-6db7d105881f
Feed Name: GBHackers
Threat Score
Attackers distributed a trojanized Proxifier installer on GitHub to deliver a fileless, multi-stage ClipBanker campaign that weakens Microsoft Defender, runs obfuscated PowerShell from registry and scheduled tasks, injects shellcode into legitimate processes, and continually monitors and replaces cryptocurrency wallet addresses to redirect funds; Kaspersky observed over 2,000 detections primarily in India and Vietnam.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
