Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The EPA Desires to Roll Again Emissions Controls on Energy Vegetation

    June 12, 2025

    Photonic processor may streamline 6G wi-fi sign processing | MIT Information

    June 12, 2025

    The AI Revolution Is a Knowledge Revolution: Why Storage Issues Extra Than Ever

    June 12, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Printer Firm Distributes Malicious Drivers Contaminated with XRed Malware
    AI Ethics & Regulation

    Printer Firm Distributes Malicious Drivers Contaminated with XRed Malware

    Declan MurphyBy Declan MurphyMay 17, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Printer Firm Distributes Malicious Drivers Contaminated with XRed Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Procolored, a printer manufacturing firm, has been discovered distributing software program drivers contaminated with malicious code, together with the infamous XRed backdoor malware.

    The problem got here to gentle when Cameron Coward, a YouTuber behind the channel Serial Hobbyism, tried to evaluate a $6,000 UV printer and encountered antivirus alerts upon plugging in a USB drive containing the printer software program.

    The alerts flagged a USB-spreading worm and a Floxif an infection, a extreme file infector identified for attaching itself to Transportable Executable recordsdata and spreading throughout community shares and detachable drives.

    – Commercial –

    This incident prompted an in-depth investigation into Procolored’s publicly accessible software program downloads, hosted on mega.nz for six printer fashions, revealing a widespread malware distribution affecting 39 recordsdata, 20 of which had distinctive hashes.

    Uncovering a Severe Safety Breach

    An in depth evaluation of the contaminated recordsdata recognized two main threats: Win32.Backdoor.XRedRAT.A, a Delphi-based backdoor beforehand documented by eSentire in February 2024, and MSIL.Trojan-Stealer.CoinStealer.H, a .NET-based clipbanker dubbed SnipVex.

    XRed Malware
    Malcat reveals XRed model 106 within the RCDATA/EXEVSNX useful resource

    The XRed backdoor, current in recordsdata like PrintExp.exe (SHA256: 531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434), facilitates keylogging, file downloads, screenshots, and distant command execution through a cmd.exe shell.

    Curiously, its command-and-control servers have been offline since early 2024, limiting lively distant exploitation dangers.

    Nonetheless, the SnipVex virus, a prepending file infector, poses a persistent risk by focusing on .exe recordsdata throughout logical drives, changing Bitcoin addresses within the clipboard to divert transactions to the attacker’s pockets, which blockchain information present gathered roughly $100,000.

    SnipVex’s an infection mechanism contains an an infection marker (0x0A 0x0B 0x0C) to forestall superinfection and avoids system directories like %TEMP%, however its presence in legit software program bundles suggests negligence in Procolored’s construct or distribution methods, possible resulting from absent or failed antivirus scanning.

    Malware Particulars and Potential Influence

    Procolored initially dismissed the antivirus alerts as false positives however eliminated the downloads from their web site round Might 8, 2025, after persistent issues.

    Upon being supplied with detailed malware evaluation, the corporate acknowledged the potential of an infection throughout USB-based software program transfers and dedicated to rigorous safety checks earlier than re-uploading recordsdata.

    XRed Malware
    Procolored.com web site

    They’ve since offered clear software program packages to affected customers and issued steering for patrons to revoke any antivirus exclusions set for his or her software program.

    For these doubtlessly contaminated, consultants suggest a full system reformat and OS reinstallation because of the irreversible injury brought on by file infectors like SnipVex, although unique recordsdata could also be recoverable by truncating the virus payload in non-superinfected situations.

    In line with the Report, this case underscores the essential want for strong safety practices in software program distribution, particularly for {hardware} distributors whose merchandise are trusted by customers.

    Whereas hypothesis about intentional malware planting exists, the outdated nature of XRed and the inactive C2 infrastructure counsel unintentional contamination over malice.

    Procolored’s ongoing efforts to remediate the difficulty are a step ahead, however the incident serves as a cautionary story for customers to stay vigilant about software program sources, even from official distributors.

    Indicators of Compromise (IoCs)

    Malware Sort Identifier
    XRed Backdoor SHA256 531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434
    SnipVex Virus SHA256 39df537aaefb0aa31019d053a61fabf93ba5f8f3934ad0d543cde6db1e8b35d1
    SnipVex BTC Pockets Handle 1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj
    SnipVex Run Keys Registry Path HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunScdBcd, ClpBtcn

    Discover this Information Fascinating! Observe us on Google Information, LinkedIn, & X to Get Immediate Updates!

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Former Black Basta Members Use Microsoft Groups and Python Scripts in 2025 Assaults

    June 12, 2025

    Interpol Dismantles 20,000 Malicious IPs and Domains Tied to 69 Malware Variants

    June 11, 2025

    The crucial function that partnerships play in shrinking the cyber abilities hole

    June 11, 2025
    Top Posts

    The EPA Desires to Roll Again Emissions Controls on Energy Vegetation

    June 12, 2025

    How AI is Redrawing the World’s Electrical energy Maps: Insights from the IEA Report

    April 18, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025
    Don't Miss

    The EPA Desires to Roll Again Emissions Controls on Energy Vegetation

    By Sophia Ahmed WilsonJune 12, 2025

    The US Environmental Safety Company moved to roll again emissions requirements for energy crops, the…

    Photonic processor may streamline 6G wi-fi sign processing | MIT Information

    June 12, 2025

    The AI Revolution Is a Knowledge Revolution: Why Storage Issues Extra Than Ever

    June 12, 2025

    Prioritizing Belief in AI – Unite.AI

    June 12, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.