Key Takeaways:
- Procolored’s official driver downloads contained XRedRAT (a distant entry trojan) and SnipVex (a Bitcoin clipboard hijacker).
- The malware, linked from Procolored’s personal assist website, swapped copied Bitcoin addresses to redirect funds to attackers, netting round 9.3 BTC.
- After public publicity, Procolored’s dad or mum firm, Tiansheng, eliminated the contaminated information, blaming the breach on USB cross-contamination.
Chinese language printer producer Procolored has been discovered distributing malware via its official printer drivers, exposing customers to severe cybersecurity dangers. The malicious software program, which included a distant entry trojan and a cryptocurrency stealer, seems to have been embedded in Procolored’s companion software program for at the very least six months.
Procolored, based mostly in Shenzhen, China, focuses on digital printing options reminiscent of DTF, UV, and DTG printers.
Since its founding in 2018, the corporate has expanded quickly, promoting in over 30 nations, together with the U.S., the place it has an enormous buyer base.
Malware Present in Procolored Printer Software program, Impacting Customers Globally
Based on native information media, the problem got here to mild when YouTuber Cameron Coward, often called Serial Hobbyism, detected malware on his system after putting in drivers for a $7,000 Procolored UV printer. His antivirus flagged a worm often called Floxif.
Coward initially contacted the corporate, which denied any wrongdoing and claimed the alert was a false optimistic. “If I attempt to obtain the information from their web site or unzip the information on the USB drive they gave me, my laptop instantly quarantines them,” Coward stated.
Searching for readability, Coward turned to Reddit for assist. That led to a deeper investigation by Karsten Hahn, a researcher at cybersecurity agency G Information.
Hahn confirmed the presence of two items of malware: XRedRAT, a distant entry trojan able to keystroke logging and distant management, and SnipVex, a beforehand unknown clipboard hijacker focusing on Bitcoin addresses.
The malware was traced to at the very least six Procolored printer fashions, with contaminated information hosted on Mega, linked immediately from Procolored’s official assist website. A complete of 39 compromised information had been discovered.
The malware changed copied Bitcoin pockets addresses with ones managed by attackers, stealing funds from unsuspecting customers.
A complete of 9.3 BTC price over $953,000 has been stolen, in response to the report. Crypto monitoring and compliance agency Sluggish Mist described how the malware operates in a Could 19 X submit:
“The official driver supplied by this printer carries a backdoor program. It is going to hijack the pockets handle within the person’s clipboard and substitute it with the attacker’s handle.“
The official driver supplied by this printer carries a backdoor program. It is going to hijack the pockets handle within the person's clipboard and substitute it with the attacker's handle: 1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj
Based on @MistTrack_io, the attacker has stolen 9.3086… https://t.co/DHCkEpHhuH pic.twitter.com/W1AnUpswLU
— MistTrack
(@MistTrack_io) Could 19, 2025
G Information contacted Tiansheng, the dad or mum firm of Procolored. The agency responded that it had eliminated the affected drivers and rescanned all information as of Could 8, 2025.
The corporate claimed the an infection doubtless occurred throughout USB transfers between methods earlier than the information had been uploaded on-line.
Customers at the moment are urged to scan their methods totally. Specialists advocate a full system reinstall for anybody who has used the contaminated drivers. New, clear driver information are reportedly accessible however should be requested immediately from Tiansheng’s technical assist.
Chinese language Marketplaces and US Fronts Gas Southeast Asian Fraud Rings
The invention of Bitcoin-stealing malware in Procolored’s official printer drivers comes amid a wider wave of cybercrime infrastructure originating in China and spreading throughout Southeast Asia.
On Could 18, blockchain agency Elliptic linked a Colorado-incorporated entity to a Chinese language-language Telegram market referred to as Xinbi Assure, a platform used to facilitate large-scale crypto scams.

Xinbi has processed over $8.4 billion in stablecoin transactions, primarily USDT, since its inception. The platform gives illicit companies starting from cash laundering and faux IDs to tech {hardware} and stolen private knowledge.
It operates on a “assure” mannequin, requiring vendor deposits to take care of belief amongst criminals.
Xinbi was registered within the U.S. in 2022 underneath the title Xinbi Co. Ltd. The corporate was flagged as delinquent in early 2025 for failing to file reviews. Elliptic suggests the group’s crypto exercise may be tied to North Korean hackers.
Xinbi follows Huione Assure, one other Chinese language market uncovered in 2024 for facilitating $98 billion in transactions.
These networks reveal a rising underground economic system powered by stablecoins and an alarming rise in cyber fraud.
The submit Procolored Printer Drivers Slip Bitcoin-Stealing Trojan, Draining $950K from Customers appeared first on Cryptonews.
The official driver supplied by this printer carries a backdoor program. It is going to hijack the pockets handle within the person's clipboard and substitute it with the attacker's handle: 1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj
Based on @MistTrack_io, the attacker has stolen 9.3086… https://t.co/DHCkEpHhuH pic.twitter.com/W1AnUpswLU