logo

DigitalPulse Proxyware Being Distributed Through Ad Pages

ID: 32d06eb1-174b-5db8-a556-3f7a94a23e60

STIX ID: report--32d06eb1-174b-5db8-a556-3f7a94a23e60

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-01-12

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC describes an active proxyjacking campaign distributing DigitalPulse proxyware via ad/pop-up pages on freeware sites: users downloading a YouTube-downloader-type executable are redirected to malicious ads that install a disguised downloader (AutoClicker) which uses anti-VM/sandbox checks, deploys a PowerShell downloader and NodeJS-executed JavaScript, then fetches and installs proxyware (signed with a Netlink Connect certificate) and persists via scheduled tasks; the report includes behavior detections, file hashes and URLs as IOCs and warns users to avoid ad/pop-up installers and to use V3 products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.