Proxyware Being Distributed Through Ad Pages
Essential information
- Published
- 21/01/2025 18:16
- Modified
- 21/01/2025 18:48
- Tags
- 2025-01-21 adware autoclicker digitalpulse downloader javascript lummac2 powershell proxyware
- Related entities
- 3 observables, 7 techniques (mitre), 3 malware
Description
Security researchers have confirmed the unauthorized installation of proxyware on systems through advertisement pages from freeware software sites. The proxyware, identified as DigitalPulse, allows threat actors to share a portion of the system's Internet bandwidth for financial gain without user consent. The campaign involves a downloader disguised as an auto-clicker program that employs various anti-analysis techniques. It ultimately installs DigitalPulse proxyware, signed with a Netlink Connect certificate, through a series of PowerShell and JavaScript routines. Users are advised to exercise caution when installing executable files from untrusted sources to prevent such infections.