216.73.217.69

Proxyware Being Distributed Through Ad Pages

· Published 21/01/2025 18:16 · Modified 21/01/2025 18:48

Export JSON

Essential information

Published
21/01/2025 18:16
Modified
21/01/2025 18:48
Tags
2025-01-21 adware autoclicker digitalpulse downloader javascript lummac2 powershell proxyware
Related entities
3 observables, 7 techniques (mitre), 3 malware

Description

Security researchers have confirmed the unauthorized installation of on systems through advertisement pages from freeware software sites. The , identified as , allows threat actors to share a portion of the system's Internet bandwidth for financial gain without user consent. The campaign involves a disguised as an auto-clicker program that employs various anti-analysis techniques. It ultimately installs , signed with a Netlink Connect certificate, through a series of and routines. Users are advised to exercise caution when installing executable files from untrusted sources to prevent such infections.

External references