Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Bitcoin malware discovered: Chinese printer manufacturer involved

Newsroom by Newsroom
May 21, 2025
in Bitcoin
virus
Share on FacebookShare on TwitterShare on Linkedin

A Chinese printer company inadvertently distributed malware that steals Bitcoin through its official drivers, resulting in the theft of over $950,000.

According to local media outlet Landian News, a Chinese printer manufacturer was found to have unknowingly distributed malware designed to steal Bitcoin through its official device drivers.

Procolored, a Shenzhen-based printer company, distributed malware capable of stealing Bitcoin alongside the official drivers for its devices. The company reportedly used USB devices to spread infected drivers and uploaded the compromised software to globally accessible cloud storage services.

Crypto security and compliance firm SlowMist explained how the malware works in a post on X:

🚨 The official driver provided by this printer carries a backdoor program. It will hijack the wallet address in the user's clipboard and replace it with the attacker's address: 1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj

🕵️ According to @MistTrack_io, the attacker has stolen 9.3086… https://t.co/DHCkEpHhuH pic.twitter.com/W1AnUpswLU

— MistTrack🕵️ (@MistTrack_io) May 19, 2025

The consequences of the breach have been significant, with a total of 9.3 BTC stolen — equivalent to over $950,000.

The issue was first flagged by YouTuber Cameron Coward, whose antivirus software detected malware in the drivers during a test of a Procolored UV printer. The software identified both a worm and a trojan virus named Foxif.

When contacted, Procolored denied the accusations, dismissing the antivirus warning as a false positive. Coward then turned to Reddit, where he shared the issue with cybersecurity professionals, drawing the attention of security firm G Data.

G Data’s investigation revealed that most of Procolored’s drivers were hosted on the MEGA file-sharing platform, with uploads dating back to October 2023. Their analysis confirmed the presence of two separate malware strains: the Win32.Backdoor.XRedRAT.A backdoor and a crypto-stealer designed to replace clipboard wallet addresses with those controlled by the attacker.

G Data reached out to Procolored, which stated that it had removed the infected drivers from its storage as of May 8 and had re-scanned all files. The company attributed the malware to a supply chain compromise, saying the malicious files were introduced via infected USB devices before being uploaded online.

Landian News recommended that users who downloaded Procolored drivers in the past six months “immediately run a full system scan using antivirus software.” However, given that antivirus tools are not always reliable, the Chinese media outlet suggested that a full system reset is the safest option when in doubt.

Previous Post

JPMorgan to allow clients to buy Bitcoin ETFs: no custody services

Next Post

Bitcoin in Strive’s sights: 75,000 BTC from Mt. Gox among its targets

Latest News

Claude Mythos AI: exploit su Apple M5 sviluppato in meno di una settimana
Bitcoin

Claude Mythos AI: exploit on Apple M5 developed in less than a week

by Newsroom
May 15, 2026
0

Security startup Calif claims to have used a preview version of Claude Mythos to build a working exploit against Apple...

Read moreDetails
MARA vende 20.880 BTC per $1,5 miliardi mentre JPMorgan chiama Bitcoin il nuovo oro
Bitcoin

MARA sells 20,880 BTC for $1.5 billion as JPMorgan calls Bitcoin the new gold

by Newsroom
May 14, 2026
0

MARA Holdings liquidates Bitcoin to fund AI expansion and reduce debt, while JPMorgan records three consecutive months of inflows into...

Read moreDetails
Claude recupera un wallet Bitcoin da $400.000 dopo 11 anni
Bitcoin

Claude recovers a $400,000 Bitcoin wallet after 11 years

by Newsroom
May 14, 2026
0

A user regained access to 5 forgotten BTC thanks to Anthropic's artificial intelligence, which identified an old wallet.dat file.

Read moreDetails
Square: superato il milione di merchant abilitati ai pagamenti Bitcoin
Bitcoin

Square: over one million merchants enabled for Bitcoin payments

by Newsroom
May 13, 2026
0

Block Inc. automatically activated BTC payments via Lightning Network for approximately one million US merchants starting March 30.

Read moreDetails
Bhutan: governo trasferisce altri 100 BTC, deflussi 2026 superano $230 milioni
Bitcoin

Bhutan: government transfers another 100 BTC, 2026 outflows exceed $230 million

by Newsroom
May 12, 2026
0

The government of Bhutan has moved 100.44 BTC worth $8.2 million, with reserves still standing at 3,119 BTC.

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.