#Proxyware
A fake corepack site at corepack[.]org is impersonating the Node.js Corepack tool and pushing malware to developers.

The download button drops an infostealer that steals browser data and SSH keys, plus proxyware that turns your machine into a proxy node.

socket.dev/blog/fake-co...
Fake Corepack Site Distributes Infostealer and Proxyware to ...
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
socket.dev
July 24, 2026 at 6:30 PM
Larva-25012 resumed Proxyware distribution in H2 2026, abusing already infected systems with DPLoader, PowerShell downloaders, scheduled tasks, and sideloading to install Proxyware and disable defenses in Korea. #Larva25012 #Korea #Proxyware
Larva-25012: A 2026 Proxyware Distribution Campaign By The Threat Actor (DigitalPulse, SOAX, Appsalt, IPRoyal)
ASEC reports that Larva-25012 resumed distributing Proxyware in the second half of 2026 by exploiting already infected systems, with recent cases involving DigitalPulse, SOAX, Appsalt, and IPRoyal. The campaign uses DPLoader, PowerShell downloaders, scheduled tasks, and loader/DLL sideloading to install Proxyware and disable defenses on systems in Korea. #Larva-25012 #DPLoader #DigitalPulse...
www.hendryadrian.com
September 22, 2026 at 8:45 AM
YouTube動画ダウンロードサイトで拡散するプロキシウェアマルウェア(2)
#CybersecurityNews
asec.ahnlab.com/en/89787/
Proxyware Malware Being Distributed on YouTube Video Download Site - 2 - ASEC
Proxyware Malware Being Distributed on YouTube Video Download Site - 2 ASEC
asec.ahnlab.com
September 5, 2025 at 7:21 AM
Proxyware Crew Sells Privacy, Prague Sells Delays, Everyone Pretends This Is Fine
PANIC 58% | Lag 0.67h | Larva-25012 is a 2026 proxyware distribution campaign tied to DigitalPulse, SOAX, Appsalt, and IPRoy
#AfterShockIndex
READ MORE
September 22, 2026 at 11:30 AM
YouTube Downloader Sites Are Now Hiding Proxyware to Hijack Your Bandwidth
YouTube Downloader Sites Are Now Hiding Proxyware to Hijack Your Bandwidth
A new report reveals that malicious YouTube video downloader sites are tricking users into installing Proxyware, a type of malware that hijacks network bandwidth.
securityonline.info
August 23, 2025 at 6:18 PM
📢 Larva-25012 : campagne de distribution de Proxyware via DPLoader en 2026

AhnLab ASEC, publié le 17 septembre 2026. L'article documente la reprise active d'une campagne de proxyjacking menée par le groupe Larva-25012, actif…

🟢 vérification factuelle haute
#DPLoader #Larva25012 #Cyberveille
Larva-25012 : campagne de distribution de Proxyware via DPLoader en 2026
AhnLab ASEC, publié le 17 septembre 2026. L'article documente la reprise active d'une campagne de proxyjacking menée par le groupe Larva-25012, actif depuis au moins 2025, ciblant principalement des systèmes en Corée du Sud.
cyberveille.ch
September 23, 2026 at 8:00 PM
Sekoia has identified Mimo, a threat actor that exploits a recently patched Craft CMS zero-day to deploy its own loader, cryptominers, and residential proxyware on hacked websites

The operators appear to be based in the Middle East

blog.sekoia.io/the-sharp-ta...
The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.
blog.sekoia.io
May 27, 2025 at 4:32 PM
Larva-25012 skips new infections - it just weaponizes existing DPLoader hosts for proxyjacking. https://intel.threadlinqs.com/threat/TL-2026-2612 #ThreatIntel #DPLoader #DigitalPulse #SOAX
September 22, 2026 at 2:08 PM
SEO的にちゃんと常に出てくるんだなー。ブロックしておこ "Fake Corepack Site Distributes Infostealer and Proxyware to ..." https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware
July 26, 2026 at 12:05 AM
Proxyware Malware Mimic as YouTube Video Download Site Delivers Malicious Javascripts
Proxyware Malware Mimic as YouTube Video Download Site Delivers Malicious Javascripts
cybersecuritynews.com
August 25, 2025 at 5:13 PM
🧀 The Sharp Taste of #Mimo’lette: Analyzing Mimo’s Latest Campaign targeting #Craft CMS

blog.sekoia.io/the-sharp-ta...
The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.
blog.sekoia.io
May 27, 2025 at 1:16 PM
Many LG and Samsung smart TV apps secretly include proxyware, exposing users to security risks. #SmartTV #CyberSecurity #Privacy #IoT #Proxyware #SecurityNews thedailytechfeed.com/smart-tv-app...
June 25, 2026 at 12:38 PM
SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
https://isc.sans.edu/podcastdetail/9572
August 15, 2025 at 2:00 AM
Proxyware Expands Program into Virginia K-12 Schools to Protect Children from Digital Harm

 Proxyware, a digital citizen protection company dedicated to safeguarding vulnerable populations, announced today the expansion of its program into Virginia schools to reduce child exploitation and digital…
Proxyware Expands Program into Virginia K-12 Schools to Protect Children from Digital Harm
 Proxyware, a digital citizen protection company dedicated to safeguarding vulnerable populations, announced today the expansion of its program into Virginia schools to reduce child exploitation and digital harm. Already this calendar year, Proxyware has detected more than 192,000 digital attacks targeting Virginia K-12 school children, underscoring the urgent need for comprehensive protection. Children across the Commonwealth face relentless digital threats.
itnerd.blog
October 6, 2025 at 2:46 PM
#Windows #Proxyware #SouthKorea #ThreatResearch AhnLab alerts users to a new proxyjacking attack via ad pages on freeware sites, infecting over 400,000 Windows systems. Beware of AutoClicker hijacking Internet... https://www.hendryadrian.com/digitalpulse-proxyware-being-distributed-through-ad-pages/
January 16, 2025 at 9:04 AM
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
thehackernews.com
June 25, 2026 at 1:27 PM
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware
thehackernews.com
May 28, 2025 at 12:04 PM
📌 Proxyware Infections via K-Lite Codec Pack: A Growing Threat in Residential Networks https://www.cyberhub.blog/article/14006-proxyware-infections-via-k-lite-codec-pack-a-growing-threat-in-residential-networks
Proxyware Infections via K-Lite Codec Pack: A Growing Threat in Residential Networks
The discovery of proxyware infections through the K-Lite Codec Pack highlights a growing concern in the cybersecurity landscape. Proxyware, which turns infected machines into proxy servers, has been found in the systems of a cybersecurity professional's family members. The software, attributed to Infatica and Digital Pulse, was inadvertently installed via a seemingly legitimate software bundle, raising questions about the ethical practices of proxy providers and the prevalence of such infections. Proxyware operates by leveraging the infected machine's resources to route internet traffic, often for malicious purposes such as web scraping, ad fraud, or other cybercriminal activities. The use of residential proxies, which are IP addresses provided by Internet Service Providers (ISPs) to homeowners, makes these activities harder to detect and block, as they appear to originate from legitimate residential networks. The implications of such infections are significant. Unauthorized data transmission can lead to privacy violations and potential legal issues for the unwitting participants. Moreover, the infected machines can become entry points for further malware infections, compromising the overall security of the network. From a cybersecurity perspective, this incident underscores the importance of vigilance when downloading software, even from seemingly reputable sources. The K-Lite Codec Pack, a popular multimedia software bundle, serves as a reminder that malware can be hidden in plain sight. Users are advised to employ robust antivirus solutions, regularly monitor network activity for anomalies, and exercise caution when installing software from the internet. While companies like Infatica and Digital Pulse may not be household names, their activities are well-documented within cybersecurity circles. The use of proxyware to build residential proxy networks is a known tactic, and the prevalence of such infections suggests a need for greater awareness and preventive measures among users and organizations alike. In conclusion, the discovery of proxyware infections via the K-Lite Codec Pack serves as a stark reminder of the evolving tactics employed by cybercriminals. By understanding the technical implications and adopting proactive security measures, users can better protect themselves against such threats.
www.cyberhub.blog
October 5, 2025 at 10:20 AM
A crew AhnLab tracks as Larva-25012 is installing bandwidth-sharing software on PCs it compromised months ago, disguising it as Microsoft Copilot and Windows security services. Victims lose their internet connection to somebody else's profit, and nothing ever looks broken.

#databreach #infosec
Proxyware hides as a Copilot service on hijacked PCs
Cyber Incidents · IntelFusions threat intelligence
www.intelfusions.com
September 22, 2026 at 10:52 AM
Lorikazz Botnet: How Android TV & STB Hijacking Leverages Tor onion C2 and ENS for Proxyware Operations – A Deep Dive into IoT Malware Evolution + Video

Introduction: The convergence of IoT botnets with privacy-centric technologies like Tor and blockchain-based naming systems marks a dangerous…
Lorikazz Botnet: How Android TV & STB Hijacking Leverages Tor onion C2 and ENS for Proxyware Operations – A Deep Dive into IoT Malware Evolution + Video
Introduction: The convergence of IoT botnets with privacy-centric technologies like Tor and blockchain-based naming systems marks a dangerous evolution in malware tactics. The newly discovered Lorikazz botnet specifically targets Android TV and set-top boxes (STBs), disguising ELF payloads as system libraries while using Tor .onion domains for command-and-control (C2) and Ethereum Name Service (ENS) for resilient domain resolution. This article dissects the technical architecture of Lorikazz, provides hands-on detection and analysis commands, and outlines mitigation strategies for security professionals.
undercodetesting.com
April 16, 2026 at 6:08 PM
A residential IP feels safe because it's someone's actual house. This week: a botnet making cars route strangers' traffic, and a proxyware app spinning up ~1,000 fresh home exit IPs an hour. When a pool churns that fast, a score on one address barely means anything. New Reputation Radar:
Reputation Radar #8: Reputation You Can Borrow
How attackers rent the trust of ordinary homes, cars, and CDNs so their traffic looks normal, and why a residential IP shouldn't round up to safe.
www.reput.io
August 26, 2026 at 2:07 PM
Fake Corepack Site Distributes Infostealer and Proxyware to Developers

huntaegis.com
July 28, 2026 at 8:16 AM
Fake Corepack Site Distributes Infostealer and Proxyware to Developers

huntaegis.com
July 27, 2026 at 9:52 AM
Proxyware actor behind fake 7-Zip is bigger than you think!: www.infoblox.com/blog/threat-...
Proxyware actor behind fake 7-Zip is bigger than you think!
Learn how a threat actor runs an end-to-end residential proxy business using lookalike domains, fake software downloads, and a connection to Chinese IPIDEA.
www.infoblox.com
July 26, 2026 at 11:12 PM