Honeygain is proxyware that has been distributed by the Larva-25012 threat actor as part of proxyjacking activity, in which victims’ internet bandwidth is monetized through unauthorized proxyware installation. AhnLab Security intelligence Center (ASEC) reported Larva-25012 has been active since at least 2024 and has distributed multiple proxyware families including Honeygain, DigitalPulse, and Infatica, with increasing targeting of systems in South Korea. The actor spreads malicious installers through malvertising and fake cracked/pirated software download pages, including lures impersonating legitimate applications such as AutoClicker, FastCleanPlus, WinMemoryCleaner, SteamCleaner, and more recently a Notepad++ installer. The broader infection chains described by ASEC use downloader malware referred to as DPLoader, persistence via Windows Task Scheduler, and command-and-control communications to receive commands and install proxyware payloads. The provided content specifically identifies Honeygain as one of the proxyware families previously installed by this actor, but does not provide Honeygain-specific technical behavior, persistence details, file paths, or indicators of compromise beyond its use as proxyware in these campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
On screen, it's a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people's internet traffic out through your living room.
In the Massive sample, the proxy session parses a server-supplied `host:port` value and opens a `net.Socket` to it. In the Honeygain/Oxylabs sample, a server message with `messageType: "connect"` supplies `address.host` and `address.port`, and later chunk messages write bytes into that connection.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial proxyware service abused in proxyjacking campaigns to monetize victim bandwidth when installed without consent.
A proxyware program used to monetize infected hosts by reselling their network bandwidth/resources; mentioned in the context of fake YouTube downloader sites distributing proxyware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.