The Chinese printing manufacturer of printers Procolored would have distributed pilots contaminated by malware that flies bitcoin. This information was released this week by the press of the Asian country and indicates that 9.3 BTC was stolen. The manufacturer informed having deleted the infected pilots, but that they had been downloaded worldwide. This problem would have been discovered thanks to the perseverance of a youtuber.

In short
- The manufacturer of Procolored printers distributes an official pilot containing malware that flies bitcoins, according to a report.
- Nearly a million dollars in Bitcoin have been stolen, according to surveillance.
- The company claims to have solved the problem, apparently discovered by a youtuber.
The manufacturer distributes pilots with a virus that flies bitcoin
The owners of a Chinese procolored printer model apparently received an unwanted gift. This is Bitcoin thief malware, according to a report by the Chinese news site Landian News.
Depending on the publication, the company would have used a flash USB key to download the software compromised by the virus to the cloud storage service for a global download. It is a green malware and a Trojan horse called Foxif.
This episode is also added to a binance study which exhibits critical faults in crypto security.
9.3 BTC stolen
According to Mistrack, malware has redirected 9.3 BTC, just under a million dollars at the time of this edition. Bitcoins went to the portfolio involved in the attack, since “The official pilot provided by this printer loads a backdoor program. He diverts the portfolio address in the user's clipboard and replaces it with the attacker's address ”according to the surveillance company.
The action of malware occurs when the user copies the address, which is modified by the virus before sending. In this case, the transfer is made to the portfolio involved in the attack.
The company is pronounced after the discovery of a youtuber
According to the report, Tiansheng Printer recognized the infection, informed that it had deleted the infected pilots and checked all the files on May 8.
However, the manufacturer's recognition would have occurred after the persistence of the youtuber Cameron Cowardwho would have discovered malware. It started when he installed the software of a PROCOLORED UV printer and was alerted by an antivirus.
Coward said that he had reported the incident to Tiansheng, who would have rejected the fault of his antivirus. Unhappy, the YouTuber looked for help on a Reddit forum and finally attracted the attention of the G-Data security company.
G-Data's analysis revealed that the pilots were contaminated by a backdoor named win32.Backdoor.xredrat.a and a cryptocurrency thief based on .NET. The latter is designed to exchange addresses in the clipboard.
The safety company advised users to carefully check the system and to scan. If possible, to reinstall the printer driver, which must be obtained by directly contacting the technical support of Tiansheng.
In the United States, Coinbase faces a wave of trials after revelations more compromised the cryptocurrency exchange platform, in connection with the May 16 hack which continues to turn turmoil.
Maximize your Cointribne experience with our 'Read to Earn' program! For each article you read, earn points and access exclusive rewards. Sign up now and start accumulating advantages.
