Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

Procolored Printer Drivers Slip Bitcoin-Stealing Trojan, Draining $950K from Users

by
May 19, 2025
in Crypto News
0
Procolored Printer Drivers Slip Bitcoin-Stealing Trojan, Draining $950K from Users
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Key Takeaways:

Procolored’s official driver downloads contained XRedRAT (a remote access trojan) and SnipVex (a Bitcoin clipboard hijacker). The malware, linked from Procolored’s own support site, swapped copied Bitcoin addresses to redirect funds to attackers, netting around 9.3 BTC. After public exposure, Procolored’s parent company, Tiansheng, removed the infected files, blaming the breach on USB cross-contamination.

Chinese printer manufacturer Procolored has been found distributing malware through its official printer drivers, exposing users to serious cybersecurity risks. The malicious software, which included a remote access trojan and a cryptocurrency stealer, appears to have been embedded in Procolored’s companion software for at least six months.

Procolored, based in Shenzhen, China, specializes in digital printing solutions such as DTF, UV, and DTG printers.

Since its founding in 2018, the company has expanded rapidly, selling in over 30 countries, including the U.S., where it has a big customer base.

Malware Found in Procolored Printer Software, Impacting Users Globally

According to local news media, the issue came to light when YouTuber Cameron Coward, known as Serial Hobbyism, detected malware on his system after installing drivers for a $7,000 Procolored UV printer. His antivirus flagged a worm known as Floxif.

Coward initially contacted the company, which denied any wrongdoing and claimed the alert was a false positive. “If I try to download the files from their website or unzip the files on the USB drive they gave me, my computer immediately quarantines them,” Coward said.

Seeking clarity, Coward turned to Reddit for help. That led to a deeper investigation by Karsten Hahn, a researcher at cybersecurity firm G Data.

Hahn confirmed the presence of two pieces of malware: XRedRAT, a remote access trojan capable of keystroke logging and remote control, and SnipVex, a previously unknown clipboard hijacker targeting Bitcoin addresses.

The malware was traced to at least six Procolored printer models, with infected files hosted on Mega, linked directly from Procolored’s official support site. A total of 39 compromised files were found.

The malware replaced copied Bitcoin wallet addresses with ones controlled by attackers, stealing funds from unsuspecting users.

A total of 9.3 BTC worth over $953,000 has been stolen, according to the report. Crypto tracking and compliance firm Slow Mist described how the malware operates in a May 19 X post:

“The official driver provided by this printer carries a backdoor program. It will hijack the wallet address in the user’s clipboard and replace it with the attacker’s address.“

The official driver provided by this printer carries a backdoor program. It will hijack the wallet address in the user’s clipboard and replace it with the attacker’s address: 1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj

According to @MistTrack_io, the attacker has stolen 9.3086… https://t.co/DHCkEpHhuH pic.twitter.com/W1AnUpswLU

— MistTrack (@MistTrack_io) May 19, 2025

G Data contacted Tiansheng, the parent company of Procolored. The firm responded that it had removed the affected drivers and rescanned all files as of May 8, 2025.

The company claimed the infection likely occurred during USB transfers between systems before the files were uploaded online.

Users are now urged to scan their systems thoroughly. Experts recommend a full system reinstall for anyone who has used the infected drivers. New, clean driver files are reportedly available but must be requested directly from Tiansheng’s technical support.

Chinese Marketplaces and US Fronts Fuel Southeast Asian Fraud Rings

The discovery of Bitcoin-stealing malware in Procolored’s official printer drivers comes amid a wider wave of cybercrime infrastructure originating in China and spreading across Southeast Asia.

On May 18, blockchain firm Elliptic linked a Colorado-incorporated entity to a Chinese-language Telegram marketplace called Xinbi Guarantee, a platform used to facilitate large-scale crypto scams.

Source: Elliptic

Xinbi has processed over $8.4 billion in stablecoin transactions, primarily USDT, since its inception. The platform offers illicit services ranging from money laundering and fake IDs to tech hardware and stolen personal data.

It operates on a “guarantee” model, requiring vendor deposits to maintain trust among criminals.

Xinbi was registered in the U.S. in 2022 under the name Xinbi Co. Ltd. The company was flagged as delinquent in early 2025 for failing to file reports. Elliptic suggests the group’s crypto activity may also be tied to North Korean hackers.

Xinbi follows Huione Guarantee, another Chinese marketplace exposed in 2024 for facilitating $98 billion in transactions.

These networks reveal a growing underground economy powered by stablecoins and an alarming rise in cyber fraud.

The post Procolored Printer Drivers Slip Bitcoin-Stealing Trojan, Draining $950K from Users appeared first on Cryptonews.

Previous Post

Trump hails cooperative effort at anti-revenge porn bill signing: ‘Bipartisanship is still possible’

Next Post

Circle’s $5B Showdown: Will Coinbase Outbid Ripple After Rejected Offer?

Next Post
Circle’s $5B Showdown: Will Coinbase Outbid Ripple After Rejected Offer?

Circle’s $5B Showdown: Will Coinbase Outbid Ripple After Rejected Offer?

  • Trending
  • Comments
  • Latest
‘Mass surveillance’: Conservatives sound alarm over Trump admin’s REAL ID rollout

‘Mass surveillance’: Conservatives sound alarm over Trump admin’s REAL ID rollout

April 17, 2025
Why Bitcoin Might Be About to Turn Bullish Again

Why Bitcoin Might Be About to Turn Bullish Again

April 18, 2025
Dogecoin Price Skyrockets 17.7% This Week: DOGE’s $27.8B Market Cap Now Towers Over Cardano – What’s Next?

Dogecoin Price Skyrockets 17.7% This Week: DOGE’s $27.8B Market Cap Now Towers Over Cardano – What’s Next?

April 27, 2025
On air, ’60 Minutes’ reporter says ‘none of us is happy’ about changes that led top producer to quit

On air, ’60 Minutes’ reporter says ‘none of us is happy’ about changes that led top producer to quit

April 28, 2025
High-grade results incl 16m @ 8g/t Au in Menzies drilling

High-grade results incl 16m @ 8g/t Au in Menzies drilling

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
High-grade results incl 16m @ 8g/t Au in Menzies drilling

High-grade results incl 16m @ 8g/t Au in Menzies drilling

May 20, 2025
South Korean Experts Warn Seoul of Mounting ‘Stablecoin Danger’

South Korean Experts Warn Seoul of Mounting ‘Stablecoin Danger’

May 20, 2025
Roman Storm’s Defense Team Accuses U.S. Government Of Withholding Key Exculpatory Evidence

Roman Storm’s Defense Team Accuses U.S. Government Of Withholding Key Exculpatory Evidence

May 19, 2025
Dogecoin Price Prediction: One Break Above $0.230 Could Unleash a Full-Blown Meme Rally

Dogecoin Price Prediction: One Break Above $0.230 Could Unleash a Full-Blown Meme Rally

May 19, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    High-grade results incl 16m @ 8g/t Au in Menzies drilling

    High-grade results incl 16m @ 8g/t Au in Menzies drilling

    May 20, 2025
    South Korean Experts Warn Seoul of Mounting ‘Stablecoin Danger’

    South Korean Experts Warn Seoul of Mounting ‘Stablecoin Danger’

    May 20, 2025
    Roman Storm’s Defense Team Accuses U.S. Government Of Withholding Key Exculpatory Evidence

    Roman Storm’s Defense Team Accuses U.S. Government Of Withholding Key Exculpatory Evidence

    May 19, 2025
    Dogecoin Price Prediction: One Break Above $0.230 Could Unleash a Full-Blown Meme Rally

    Dogecoin Price Prediction: One Break Above $0.230 Could Unleash a Full-Blown Meme Rally

    May 19, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved