- A Chinese printer manufacturer served malware with software installations for six months
- Malware included back doors and crypto stealers
- Nearly 10 BTC were stolen
Procolored, a large Chinese printer manufacturer, has inadvertently infected its customers with back doors, infostealers and cryptocurrency – for six months. This is according to cybersecurity scientists G -DATA that was tilted on the supply chain attacks by a YouTube content, Cameron Coward.
Apparently, Coward wanted to undergo one of Procolored’s printers, and after trying to install the accompanying software from a USB stick, warn was warned about the presence of FLOXIF WORM. He reached out to the company that rejected the warning as a false positive. Dissatisfied with the answer, Coward turned to Reddit, where his thread was picked up by G Data’s researchers.
The team found that six of the company’s product lines infected with malware: F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro. They also decided that the last update of the software was made in October 2024, which means the company implemented malware for at least half a year before they were discovered.
Tens of thousands of unique variants
In total, the researchers found 39 malware detections in 20 unique hayhede executable files. There were rats, Trojans, clipboard stealers and cryptocurrency stealers. One of the wallets allegedly belonging to the striker received almost 10 BTC, which means attackers rocked almost a million dollars with only one piece of malware.
It was also said that some of the Command and Control (C2) infrastructure was inactive since the beginning of 2024, while the BTC cargo book has not been active since March of that year. This could signal that the threat actors moved to other things, which could mean that the threat is not so pronounced today.
Improved is the leader in the digital textile printing industry according to Cyberinsides. The company’s hardware is used in small manufacturing and creative industries, the publication claims, adding that its presence “sent ripples” through the tech and maker communities.
From May 8, all software was removed from Procolored’s website and a study was launched. The company told G -Data that its systems were probably also compromised.
Via Bleeping computer