logo

The Proxifier Trap: The “Fileless” Marathon Stealing Your Crypto

ID: 06ce35e1-29f1-5db8-8b5b-cc5d8c98567f

STIX ID: report--06ce35e1-29f1-5db8-8b5b-cc5d8c98567f

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Kaspersky researchers report a widespread campaign (since early 2025) that lures users searching for cracked ‘Proxifier’ software to malicious GitHub links; downloads trigger a multi‑stage, largely fileless infection chain (PowerShell scripts, registry persistence, process injection) culminating in a ClipBanker clipboard‑stealer that replaces cryptocurrency addresses to divert funds, affecting over 2,000 users—predominantly in India and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.