The Proxifier Trap: The “Fileless” Marathon Stealing Your Crypto
ID: 06ce35e1-29f1-5db8-8b5b-cc5d8c98567f
STIX ID: report--06ce35e1-29f1-5db8-8b5b-cc5d8c98567f
Feed Name: securityonline.info
Threat Score
Kaspersky researchers report a widespread campaign (since early 2025) that lures users searching for cracked ‘Proxifier’ software to malicious GitHub links; downloads trigger a multi‑stage, largely fileless infection chain (PowerShell scripts, registry persistence, process injection) culminating in a ClipBanker clipboard‑stealer that replaces cryptocurrency addresses to divert funds, affecting over 2,000 users—predominantly in India and Vietnam.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
