Market Cap: $3.3401T -0.830%
Volume(24h): $100.8368B 22.900%
  • Market Cap: $3.3401T -0.830%
  • Volume(24h): $100.8368B 22.900%
  • Fear & Greed Index:
  • Market Cap: $3.3401T -0.830%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$107736.199599 USD

-1.55%

ethereum
ethereum

$2529.143076 USD

-1.90%

tether
tether

$1.000043 USD

-0.02%

xrp
xrp

$2.250949 USD

-1.15%

bnb
bnb

$658.511766 USD

-0.59%

solana
solana

$148.143585 USD

-2.85%

usd-coin
usd-coin

$0.999961 USD

0.00%

tron
tron

$0.286929 USD

-0.40%

dogecoin
dogecoin

$0.166572 USD

-4.07%

cardano
cardano

$0.574296 USD

-2.81%

hyperliquid
hyperliquid

$37.258444 USD

-6.85%

bitcoin-cash
bitcoin-cash

$494.935847 USD

-0.81%

sui
sui

$2.834432 USD

-3.49%

chainlink
chainlink

$13.227182 USD

-2.94%

unus-sed-leo
unus-sed-leo

$9.040600 USD

-0.07%

Cryptocurrency News Articles

Printer Company Caught Distributing Bitcoin-Stealing Malware

May 20, 2025 at 07:27 pm

From now on, in order to protect your bitcoin (BTC) or other cryptoassets, you'll need not only to watch what you're clicking online, but also what printer you're buying

Printer Company Caught Distributing Bitcoin-Stealing Malware

A printer company was caught distributing bitcoin (BTC)-stealing malware, researchers at G Data discovered.

First discovered by Cameron Coward, the YouTuber behind the channel Serial Hobbyism, and discussed on Reddit, the issue caught the attention of the cybersecurity firm.

Their Principal Malware Researcher, Karsten Hahn, said he discovered that the threat actor's address received 9.3 BTC ($985,000), potentially from users of printers made by Procolored. The address, which saw 330 transactions in total, is currently empty.

After the YouTuber received an antivirus alert about a USB-spreading malware and a Floxif infection, considered one of the most severe types of infection, Hahn checked downloads for six Procolored products.

Among the files, last updated in October 2024, he found Win32.Backdoor.XRedRAT.A, a backdoor, and MSIL.Trojan-Stealer.CoinStealer.H, a stealer that either exfiltrates cryptocurrency wallets or replaces addresses in the clipboard with the attackers’ address.

However, the researcher didn’t find Floxif in the download section.

Meanwhile, initially, Procolored denied that they were spreading the malware, providing various explanations as to why antivirus programs might misidentify their software as false positives.

"Nevertheless, they took down the software downloads from their website, which we noticed around the 8th of May 2025, and started an internal investigation," Hahn said, suggesting that a plausible explanation is the absence or failure of antivirus scanning on the systems used to compile and distribute the software packages.

In a response to the researcher, the company suggested that the virus was injected during the process of transferring the software from USB drives to their website. The company also claims that the software will be re-uploaded "only after passing stringent virus and security checks."

In the meantime, Hahn recommends Procolored product users check whether any antivirus exclusions have been set for the printer software files, as people might have dismissed antivirus warnings.

"The safest remedy for an infection with file infectors is reformatting all drives and reinstalling the operating system," the researcher said, adding that despite transactions to the BTC address stopping on March 3rd, 2024, the file infection itself still damages systems.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Jul 08, 2025