logo

Bandwidth Bandits: Fake Notepad++ Installers Hide “Proxyjacking” Malware

ID: 1043a4f9-d4a5-5a4d-9db0-47b036c23b22

STIX ID: report--1043a4f9-d4a5-5a4d-9db0-47b036c23b22

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

ASEC (AhnLab) warns of a Larva-25012 campaign distributing trojanized Notepad++ installers (Setup.zip containing Setup.exe and malicious TextShaping.dll) that use DLL side-loading to deploy DPLoader and proxyware (Infatica, DigitalPulse). The threat persists via scheduled tasks (including a task masquerading as "Microsoft Anti-Malware Tool"), tampers with Windows Defender settings to evade detection, and monetizes victims' internet connections through Proxyjacking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.