Honeygain is a legitimate proxyware application that monetizes users’ unused Internet bandwidth by routing third-party traffic through enrolled devices. Threat actors have abused Honeygain in proxyjacking operations by covertly installing legitimate or modified clients on compromised Windows systems and binding them to attacker-controlled accounts, diverting revenue from bandwidth sharing to the attackers. Observed malicious variants have suppressed the user interface and notifications, incorporated persistence mechanisms, and used attacker-supplied configuration or API credentials to register infected hosts. Honeygain has also been deployed alongside cryptocurrency miners and information stealers, allowing operators to derive multiple revenue streams from a single infection. Larva-25012 has been associated with the distribution of Honeygain, DigitalPulse, Infatica, and other proxyware, primarily against South Korean systems, through deceptive software-download and pirated-software lures. Unauthorized Honeygain deployment can expose victim networks to privacy, reputational, legal, and operational risks because proxy traffic appears to originate from the victim’s network.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Throughout each stage of the infection process, the malware transmits status updates by embedding the information into the User-Agent header of HTTP requests that are made.
On screen, it's a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people's internet traffic out through your living room.
In the Massive sample, the proxy session parses a server-supplied `host:port` value and opens a `net.Socket` to it. In the Honeygain/Oxylabs sample, a server message with `messageType: "connect"` supplies `address.host` and `address.port`, and later chunk messages write bytes into that connection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Service de proxyware mentionné sans détail d’utilisation opérationnelle dans le corps de l’article.
Commercial proxyware service abused in proxyjacking campaigns to monetize victim bandwidth when installed without consent.
A proxyware program used to monetize infected hosts by reselling their network bandwidth/resources; mentioned in the context of fake YouTube downloader sites distributing proxyware.
A legitimate proxyware client that attackers trojanize, patch, or silently install to monetize victim bandwidth and disguise malicious activity. The content describes modified clients with hardcoded credentials/API keys and disabled notifications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.