Bandwidth Bandits: Fake Notepad++ Installers Hide “Proxyjacking” Malware
ID: 1043a4f9-d4a5-5a4d-9db0-47b036c23b22
STIX ID: report--1043a4f9-d4a5-5a4d-9db0-47b036c23b22
Feed Name: securityonline.info
Threat Score
ASEC (AhnLab) warns of a Larva-25012 campaign distributing trojanized Notepad++ installers (Setup.zip containing Setup.exe and malicious TextShaping.dll) that use DLL side-loading to deploy DPLoader and proxyware (Infatica, DigitalPulse). The threat persists via scheduled tasks (including a task masquerading as "Microsoft Anti-Malware Tool"), tampers with Windows Defender settings to evade detection, and monetizes victims' internet connections through Proxyjacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
