DigitalPulse Proxyware Being Distributed Through Ad Pages
ID: 32d06eb1-174b-5db8-a556-3f7a94a23e60
STIX ID: report--32d06eb1-174b-5db8-a556-3f7a94a23e60
Feed Name: ASEC
AhnLab ASEC describes an active proxyjacking campaign distributing DigitalPulse proxyware via ad/pop-up pages on freeware sites: users downloading a YouTube-downloader-type executable are redirected to malicious ads that install a disguised downloader (AutoClicker) which uses anti-VM/sandbox checks, deploys a PowerShell downloader and NodeJS-executed JavaScript, then fetches and installs proxyware (signed with a Netlink Connect certificate) and persists via scheduled tasks; the report includes behavior detections, file hashes and URLs as IOCs and warns users to avoid ad/pop-up installers and to use V3 products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
