Chinese printer manufacturer Procolored has inadvertently distributed infected printer drivers containing malware that has been used to steal cryptocurrency from users. The malicious software, identified as a Delphi backdoor, was embedded in official device drivers and has been active since at least 2016. This malware hijacks users' clipboard wallet addresses, replacing them with the attacker's own, resulting in the theft of approximately 9.3 Bitcoin, valued at around $950,000. The malware has links to multiple cryptocurrency exchanges. This incident highlights the risks associated with downloading software from unofficial or compromised sources. Additionally, unrelated but concurrent cybersecurity threats include the compromise of the VMware tool RVTools, which was used to spread Bumblebee malware via its official site, now taken offline.
🚨 ALERT: A backdoored printer driver hijacked wallet addresses, stealing 9.3 $BTC since 2016, with ties to multiple exchanges. https://t.co/gkMFuYjLkM
NEW: 🇨🇳 Chinese printer manufacturer Procolored unknowingly distributed Bitcoin-stealing malware through its official device drivers, resulting in 9.3 BTC (💵$950K) stolen from users. https://t.co/3x5b1gCcdP
相次ぐ証券口座の乗っ取り いったい誰が何のために… 被害者のパソコンを解析し、何が起きているのかを追跡した https://t.co/LaUlJEfUvq