{"id":849706,"date":"2025-05-20T09:11:26","date_gmt":"2025-05-20T14:11:26","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/05\/20\/chinese-printer-maker-spread-bitcoin-stealing-malware-report\/"},"modified":"2025-05-20T09:11:26","modified_gmt":"2025-05-20T14:11:26","slug":"chinese-printer-maker-spread-bitcoin-stealing-malware-report","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/05\/20\/chinese-printer-maker-spread-bitcoin-stealing-malware-report\/","title":{"rendered":"Chinese printer maker spread Bitcoin stealing malware \u2014 Report"},"content":{"rendered":"<div data-gtm-locator=\"a1\" data-v-60373258>\n<article id=\"article-191902\" data-v-60373258>\n<p itemprop=\"description\" data-v-60373258> Chinese printer maker Procolored reportedly spread clipboard-hijacking Bitcoin malware via its official drivers in a supply chain attack that led to over $950,000 in stolen funds. <\/p>\n<div data-v-60373258><picture><source media=\"(min-width: 1200px)\" ><source media=\"(min-width: 992px)\" ><source media=\"(min-width: 768px)\" ><source media=\"(min-width: 480px)\" ><img  loading=\"eager\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1434\/https:\/\/s3.cointelegraph.com\/uploads\/2025-05\/0196e86a-7f87-746b-88b1-ec1d947aee2a\" alt=\"Chinese printer maker spread Bitcoin stealing malware \u2014 Report\"><\/picture><\/div>\n<div data-v-60373258>\n<div data-v-60373258>\n<p>Chinese printer manufacturer Procolored distributed Bitcoin-stealing malware alongside its official drivers, according to local media reports.<\/p>\n<p>Chinese news outlet Landian News <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.landiannews.com\/archives\/108992.html\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.landiannews.com\/archives\/108992.html\">reported<\/a> on May 19 that Shenzhen-based printer company Procolored has been distributing Bitcoin-stealing (<a data-ct-non-breakable=\"null\" href=\"http:\/\/cointelegraph.com\/bitcoin-price\" rel=\"null\" target=\"null\" title=\"null\">BTC<\/a>) malware alongside official drivers. The company reportedly used USB drivers to distribute malware-ridden drivers and uploaded the compromised software to cloud storage for global download.<\/p>\n<p>A total of 9.3 BTC worth over $953,000 have been stolen, according to the report. Crypto tracking and compliance firm Slow Mist described how the malware operates in a May 19 X <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/MistTrack_io\/status\/1924411803540590728\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/MistTrack_io\/status\/1924411803540590728\">post<\/a>:<\/p>\n<blockquote><p>\u201cThe official driver provided by this printer carries a backdoor program. It will hijack the wallet address in the user\u2019s clipboard and replace it with the attacker&#8217;s address.\u201c<\/p><\/blockquote>\n<figure><img decoding=\"async\" alt src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-05\/0196e8bf-2ad1-7841-83b8-a0e3ad79f73e\" title><figcaption><em>Source: <\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/MistTrack_io\/status\/1924411803540590728\" rel=\"nofollow noopener\" target=\"_blank\" text=\"null\" title=\"https:\/\/x.com\/MistTrack_io\/status\/1924411803540590728\"><em>MistTrack<\/em><\/a><\/figcaption><\/figure>\n<p><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/massive-supply-chain-attack-targeting-small-number-of-crypto-companies-kaspersky\" rel=\"null\" target=\"null\" text=\"null\" title=\"https:\/\/cointelegraph.com\/news\/massive-supply-chain-attack-targeting-small-number-of-crypto-companies-kaspersky\"><em><strong>Massive supply chain attack targeting small number of crypto companies: Kaspersky<\/strong><\/em><\/a><\/p>\n<h2>YouTuber flags malware in Procolored drivers<\/h2>\n<p>Landian News recommended users who downloaded Procolored printer drivers in the past six months to \u201cimmediately perform a full system scan using antivirus software.\u201d Still, given the hit or miss nature of antivirus software, a full system reset is always the better option when in doubt:<\/p>\n<blockquote><p>\u201cIdeally, you should reinstall your operating system and thoroughly check old files.\u201c<\/p><\/blockquote>\n<p>The issue was allegedly first reported by YouTuber <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.youtube.com\/@serialhobbyism_official\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.youtube.com\/@serialhobbyism_official\">Cameron Coward<\/a>, whose antivirus software detected malware in the drivers while testing a Procolored UV printer. The software flagged the drive as containing a worm and a trojan virus named Foxif.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/cyber-criminals-steal-coinbase-customer-data-20-m-ransom\" rel target=\"_self\" text=\"null\" title=\"https:\/\/cointelegraph.com\/news\/cyber-criminals-steal-coinbase-customer-data-20-m-ransom\"><em><strong>Coinbase faces $400M bill after insider phishing attack<\/strong><\/em><\/a><\/p>\n<h2>Cybersecurity company confirms crypto-stealing malware<\/h2>\n<p>When contacted, Procolored denied the claims and dismissed the antivirus tool flagging the drivers as a false positive. Coward turned to <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.reddit.com\/r\/computerviruses\/comments\/1kbkmgq\/viruses_included_in_product_im_reviewing\/\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.reddit.com\/r\/computerviruses\/comments\/1kbkmgq\/viruses_included_in_product_im_reviewing\/\">Reddit<\/a>, where he shared the issue with cybersecurity professionals, attracting the attention of cybersecurity firm G-Data.<\/p>\n<p>G-Data\u2019s <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.gdatasoftware.com\/blog\/2025\/05\/38200-printer-infected-software-downloads\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.gdatasoftware.com\/blog\/2025\/05\/38200-printer-infected-software-downloads\">investigation<\/a> found that most of Procolored\u2019s drivers were hosted on the file hosting service MEGA, with uploads as old as October 2023. Analysis of those files confirmed that they were compromised by two distinct pieces of malware: backdoor Win32.Backdoor.XRedRAT.A and a crypto stealer designed to substitute addresses in the clipboard with those controlled by the attacker.<\/p>\n<p>G-Data contacted Procolored, with the hardware producer saying it deleted the infected drivers from its storage on May 8 and re-scanned all files. Procolored attributed the malware to a supply chain compromise, stating that the malicious files were introduced through infected USB devices before being uploaded online.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/explained\/crypto-drainers-as-a-service-what-you-need-to-know\" rel target=\"_self\" text=\"null\" title=\"https:\/\/cointelegraph.com\/explained\/crypto-drainers-as-a-service-what-you-need-to-know\"><em><strong>Crypto drainers as a service: What you need to know<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\" label=\"Subscription Form: Markets Outlook\"><\/template><\/p>\n<\/div>\n<p><img decoding=\"async\" alt src=\"https:\/\/zoa.cointelegraph.com\/pixel?postId=191902&#038;regionId=1\" data-v-60373258><\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/cointelegraph.com\/news\/bitcoin-stealer-malware-found-in-official-printer-drivers?utm_source=rss_feed&#038;utm_medium=rss&#038;utm_campaign=rss_partner_inbound\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Cointelegraph by Adrian Zmudzinski<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese printer maker Procolored reportedly spread clipboard-hijacking Bitcoin malware via its official drivers in a supply chain attack that led to over $950,000 in stolen funds. Chinese printer manufacturer Procolored distributed Bitcoin-stealing malware alongside its official drivers, according to local media reports. Chinese news outlet Landian News reported on May 19 that Shenzhen-based printer company<\/p>\n","protected":false},"author":1,"featured_media":849707,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[933,35105],"tags":[],"class_list":{"0":"post-849706","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-chinese","8":"category-printer"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/849706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=849706"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/849706\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/849707"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=849706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=849706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=849706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}