Close Menu
TechurzTechurz
    What's Hot

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 2026

    Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say

    May 23, 2026

    This young startup is taking on a fragrance industry that hasn’t changed in a almost half century

    May 21, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest
    • Peec, one of Berlin’s rising startups, more than doubled annualized revenue in months to $10M, sources say
    • This young startup is taking on a fragrance industry that hasn’t changed in a almost half century
    • Maka Kids is redefining kids’ screen time with a streaming app optimized for well-being, not engagement
    • Beauty booking startup Fresha hits $1 billion valuation with KKR backing
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Guides - This Adorable Printer Shipped With Bitcoin-Stealing Malware
    Guides

    This Adorable Printer Shipped With Bitcoin-Stealing Malware

    TechurzBy TechurzMay 19, 2025Updated:May 12, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This Adorable Printer Shipped With Bitcoin-Stealing Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Printer brand Procolored unintentionally bundled malware with its official software for approximately six months. The full impact of this incident is still unknown, though customers should take action to ensure that their machines are not infected.

    Procolored occupies a strong foothold in the UV printing, direct-to-garment (DTG) printing, and direct-to-film (DTF) printing niche. Its products cost several thousand dollars and primarily appeal to small business owners who want to print shirts, stickers, or other apparel at scale.

    Reports of malware-infected Procolored drivers began cropping up in Reddit communities earlier this year. That said, the problem didn’t receive much attention until May 13th, when YouTuber Cameron Coward (Serial Hobbyism) published his review of a $7k Procolored printer at Hackster.io. Coward encountered Windows Defender antivirus warnings when attempting to download vendor-supplied software for a Procolored UV Printer—one package contained a Floxif virus, while another was flagged for a worm.

    Naturally, Coward reached out to Procolored for support. But he was told that Windows Defender made a mistake. So, he asked third-party analysts, including Karsten Hahn, Principle Malware Researcher at G DATA CyberDefense, to look the files. The analysts concluded that 39 files distributed through Procolored’s Mega file distribution page were inundated with XRedRAT and SnipVex malware.

    XRedRat is a known virus that allows threat actors to remotely access infected machines. It can capture screenshots, log keystrokes, view hard disk contents, and manipulate or delete files. However, this version of XRedRat is no longer capable of facilitating a remote connection, as its backend went offline in February 2024, long before Procolored began distributing infected software packages.

    Related

    The LOKLiK iPrinter DTF Brings High-Quality DTF Printing to Everyone

    This post is sponsored by LOKLiK.

    SnipVex is a bit more interesting—it’s a previously-unknown clipper malware that spreads itself across machines or networks by infecting executable files. Once it’s on a machine, it redirects cryptocurrency transactions to a malicious Bitcoin address, which then launders the money to reduce traceability. This address has received a total of 9.30 Bitcoin, which works out to about $100k USD, though transactions stopped on March 3rd, 2024.

    Curiously, analysts did not encounter Floxif malware on Procolored’s downloads page. Cameron Coward ran into Floxif when installing software from a USB stick supplied by Procolored, so this discrepancy may be due to differences between software executable versions.

    In any case, Floxif and XRedRat are known viruses that should be flagged by any competent antivirus software. Karsten Hahn believes that the presence of these viruses is a sign of extremely poor cybersecurity within Procolored. He believes that employees at the company used infected machines to upload official software packages, thereby spreading the infection to customers.

    There is no evidence of intentional malfeasance from Procolored. If the company wanted to hack into customers’ computers or hijack BitCoin transactions, it wouldn’t use outdated malware to do so. XRedRat and SnipVex no longer provide remote access or Bitcoin-stealing functionality. Their only remaining function is self-replication.

    Procolored took down its software downloads page and kicked off an internal investigation on May 8th. It now acknowledges that it accidentally distributed malware, and its official explanation is that “the software hosted on our website was initially transferred via USB drives … it is possible that a virus was introduced during this process.” The Procolored downloads page came back online a few days ago, and third-party analysts confirm that its software packages are now free from malware.

    Related

    I’ve Abandoned Third-Party Antivirus and I’m Never Looking Back

    More powerful and less bloated, Microsoft Security is built into Window and works incredibly well.

    Still, this story doesn’t inspire confidence in Procolored. The company failed to protect itself from basic cybersecurity threats and unwittingly sent malware to customers for nearly six months. I’m also inclined to point out an interesting footnote in Cameron Coward’s review; “I contacted Procolored support four times over the course of my testing, for help with figuring out the software and settings. Every single time, the agent requested multiple times that I allow them to connect remotely to my computer.”

    Again, this old malware is easily detectable by Windows Defender and other antivirus solutions. The big concern here is that Procolored customers may have ignored antivirus warnings when setting up a printer or installing new drivers. If you purchased a Procolored device after November 2024, check to see if there are any exceptions in your antivirus software—an exception for Visual C++ or PrintExp may indicate an infection.

    Your antivirus software should be able to remove XRedRat and Floxif infections, but SnipVex was only discovered a week ago, so it may remain undetectable. You’ll need to format your drives and reinstall your operating system to clear the infection—SnipVex can’t steal Bitcoin anymore, but it will damage your PC through replication. I suggest that affected customers read Karsten Hahn’s coverage at G Data Cybersecurity, which includes some details that may aid in file recovery.

    We’ve reached out to Procolored for a statement and will update this article if we receive a response.

    Source: Hackster.io & G DATA CyberDefense via BleepingComputer

    Adorable BitcoinStealing malware Printer Shipped
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleA drug developer is buying 23andMe – what does that mean for your DNA data?
    Next Article Google’s popular AI tool gets its own Android app – how to use NotebookLM on your phone
    Techurz
    • Website

    Related Posts

    Opinion

    Delve did the security compliance on LiteLLM, an AI project hit by malware

    March 26, 2026
    Cyber Reality

    PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs

    November 2, 2025
    Cyber Reality

    DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising

    November 1, 2025
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 202513 Views
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future-focused technology intelligence - written today, searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.