Traffmonetizer is proxyware that has been identified as one of several proxyware strains abused in proxyjacking campaigns. Reported proxyjacking activity involved unauthorized installation of proxyware to monetize victim Internet bandwidth for attacker profit. In the referenced campaigns, proxyware families abused in this manner included IPRoyal, Peer2Profit, Traffmonetizer, Proxyrack, and PacketStream. One reported intrusion set involved Python scripts injected via Selenium Grid configurations, reverse shell execution, and installation of payloads such as IPRoyal and Traffmonetizer. Separate reporting described a broader proxyjacking infection chain in which victims were lured via advertisement pop-ups on freeware download sites to install a disguised "AutoClicker" downloader on Windows systems. That downloader performed anti-VM and anti-sandbox checks, dropped a PowerShell script, installed NodeJS, executed malicious JavaScript via a scheduled task, contacted a C2 server, and received PowerShell commands to download and install proxyware from GitHub. In that campaign, the installed proxyware was assessed by ASEC as DigitalPulse signed with a "Netlink Connect" certificate; Traffmonetizer was listed as a known proxyware brand abused in similar proxyjacking cases, but the provided content does not directly attribute that specific AutoClicker/Netlink Connect chain to Traffmonetizer. Targeting in the provided content includes Windows systems and victims reached through freeware download and ad-redirect infrastructure. No Traffmonetizer-specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate proxyware service cited as being abused in proxyjacking cases to monetize victim bandwidth without consent.
Traffmonetizer is a proxyjacking tool that enables threat actors to monetize infected systems by selling their bandwidth as part of a proxy network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.