216.73.216.6

Proxyware Malware Being Distributed on YouTube Video Download Site

· Published 22/08/2025 11:05 · Modified 22/08/2025 18:55

Export JSON

Essential information

Published
22/08/2025 11:05
Modified
22/08/2025 18:55
Tags
2025-08-22 bandwidth c&c digitalpulse downloader honeygain infatica javascript malware node.js proxyware task scheduler youtube
Related entities
8 techniques (mitre), 4 malware

Description

A malicious campaign is targeting users through fake video download sites, distributing . The attack involves a disguised as WinMemoryCleaner, which installs NodeJS and runs malicious . This script then installs various programs, including , , and recently, . The uses for persistence and sends system information to a C&C server. The exploits the infected system's network for the attacker's profit. Users in South Korea have been particularly targeted. To prevent infection, users should avoid installing executables from suspicious websites and use antivirus software.

External references