Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The OnePlus 12 is still on sale for $300 off – but time is running out

    October 15, 2025

    Coinbase boosts investment in India’s CoinDCX, valuing exchange at $2.45B

    October 15, 2025

    Was ist ein Keylogger?

    October 15, 2025
    Facebook X (Twitter) Instagram
    Trending
    • The OnePlus 12 is still on sale for $300 off – but time is running out
    • Coinbase boosts investment in India’s CoinDCX, valuing exchange at $2.45B
    • Was ist ein Keylogger?
    • A minority of businesses have won big with AI. What are they doing right?
    • New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions
    • CISOs must rethink the tabletop, as 57% of incidents have never been rehearsed
    • A New Attack Lets Hackers Steal 2-Factor Authentication Codes From Android Phones
    • Leaving Windows 10 today? How to clear your new Windows 11 PC cache (and start fresh)
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Guides»This Adorable Printer Shipped With Bitcoin-Stealing Malware
    Guides

    This Adorable Printer Shipped With Bitcoin-Stealing Malware

    TechurzBy TechurzMay 19, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    This Adorable Printer Shipped With Bitcoin-Stealing Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Printer brand Procolored unintentionally bundled malware with its official software for approximately six months. The full impact of this incident is still unknown, though customers should take action to ensure that their machines are not infected.

    Procolored occupies a strong foothold in the UV printing, direct-to-garment (DTG) printing, and direct-to-film (DTF) printing niche. Its products cost several thousand dollars and primarily appeal to small business owners who want to print shirts, stickers, or other apparel at scale.

    Reports of malware-infected Procolored drivers began cropping up in Reddit communities earlier this year. That said, the problem didn’t receive much attention until May 13th, when YouTuber Cameron Coward (Serial Hobbyism) published his review of a $7k Procolored printer at Hackster.io. Coward encountered Windows Defender antivirus warnings when attempting to download vendor-supplied software for a Procolored UV Printer—one package contained a Floxif virus, while another was flagged for a worm.

    Naturally, Coward reached out to Procolored for support. But he was told that Windows Defender made a mistake. So, he asked third-party analysts, including Karsten Hahn, Principle Malware Researcher at G DATA CyberDefense, to look the files. The analysts concluded that 39 files distributed through Procolored’s Mega file distribution page were inundated with XRedRAT and SnipVex malware.

    XRedRat is a known virus that allows threat actors to remotely access infected machines. It can capture screenshots, log keystrokes, view hard disk contents, and manipulate or delete files. However, this version of XRedRat is no longer capable of facilitating a remote connection, as its backend went offline in February 2024, long before Procolored began distributing infected software packages.

    Related

    The LOKLiK iPrinter DTF Brings High-Quality DTF Printing to Everyone

    This post is sponsored by LOKLiK.

    SnipVex is a bit more interesting—it’s a previously-unknown clipper malware that spreads itself across machines or networks by infecting executable files. Once it’s on a machine, it redirects cryptocurrency transactions to a malicious Bitcoin address, which then launders the money to reduce traceability. This address has received a total of 9.30 Bitcoin, which works out to about $100k USD, though transactions stopped on March 3rd, 2024.

    Curiously, analysts did not encounter Floxif malware on Procolored’s downloads page. Cameron Coward ran into Floxif when installing software from a USB stick supplied by Procolored, so this discrepancy may be due to differences between software executable versions.

    In any case, Floxif and XRedRat are known viruses that should be flagged by any competent antivirus software. Karsten Hahn believes that the presence of these viruses is a sign of extremely poor cybersecurity within Procolored. He believes that employees at the company used infected machines to upload official software packages, thereby spreading the infection to customers.

    There is no evidence of intentional malfeasance from Procolored. If the company wanted to hack into customers’ computers or hijack BitCoin transactions, it wouldn’t use outdated malware to do so. XRedRat and SnipVex no longer provide remote access or Bitcoin-stealing functionality. Their only remaining function is self-replication.

    Procolored took down its software downloads page and kicked off an internal investigation on May 8th. It now acknowledges that it accidentally distributed malware, and its official explanation is that “the software hosted on our website was initially transferred via USB drives … it is possible that a virus was introduced during this process.” The Procolored downloads page came back online a few days ago, and third-party analysts confirm that its software packages are now free from malware.

    Related

    I’ve Abandoned Third-Party Antivirus and I’m Never Looking Back

    More powerful and less bloated, Microsoft Security is built into Window and works incredibly well.

    Still, this story doesn’t inspire confidence in Procolored. The company failed to protect itself from basic cybersecurity threats and unwittingly sent malware to customers for nearly six months. I’m also inclined to point out an interesting footnote in Cameron Coward’s review; “I contacted Procolored support four times over the course of my testing, for help with figuring out the software and settings. Every single time, the agent requested multiple times that I allow them to connect remotely to my computer.”

    Again, this old malware is easily detectable by Windows Defender and other antivirus solutions. The big concern here is that Procolored customers may have ignored antivirus warnings when setting up a printer or installing new drivers. If you purchased a Procolored device after November 2024, check to see if there are any exceptions in your antivirus software—an exception for Visual C++ or PrintExp may indicate an infection.

    Your antivirus software should be able to remove XRedRat and Floxif infections, but SnipVex was only discovered a week ago, so it may remain undetectable. You’ll need to format your drives and reinstall your operating system to clear the infection—SnipVex can’t steal Bitcoin anymore, but it will damage your PC through replication. I suggest that affected customers read Karsten Hahn’s coverage at G Data Cybersecurity, which includes some details that may aid in file recovery.

    We’ve reached out to Procolored for a statement and will update this article if we receive a response.

    Source: Hackster.io & G DATA CyberDefense via BleepingComputer

    Adorable BitcoinStealing malware Printer Shipped
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleA drug developer is buying 23andMe – what does that mean for your DNA data?
    Next Article Google’s popular AI tool gets its own Android app – how to use NotebookLM on your phone
    Techurz
    • Website

    Related Posts

    Security

    New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs

    October 14, 2025
    Security

    Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

    October 10, 2025
    Security

    The Evolution of UTA0388’s Espionage Malware

    October 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Our Picks

    The OnePlus 12 is still on sale for $300 off – but time is running out

    October 15, 2025

    Coinbase boosts investment in India’s CoinDCX, valuing exchange at $2.45B

    October 15, 2025

    Was ist ein Keylogger?

    October 15, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.