Infatica is a proxyware agent that enables proxyjacking by silently routing third-party traffic through a victim system’s Internet connection, allowing operators to monetize the victim’s bandwidth. Larva-25012 has deployed Infatica in campaigns primarily affecting Windows systems in South Korea. Observed delivery chains use deceptive advertisements and fraudulent cracked-software download portals, including trojanized installers masquerading as legitimate applications. The campaigns use staged loaders, DLL side-loading, PowerShell, and scheduled-task persistence to install proxyware. Infatica deployments have also used a scheduled task masquerading as a Microsoft security component to reduce user suspicion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Infatica’s code then uses the browser of anyone who has that extension installed to route Web traffic for the company’s customers... The end result is when Infatica customers browse to a web site, that site thinks the traffic is coming from the Internet address tied to the extension user, not the customer’s.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Service de proxyware mentionné sans détail d’utilisation opérationnelle dans le corps de l’article.
Commercial proxyware abused to hijack victim internet bandwidth (proxyjacking) and resell/relay it for attacker monetization.
Commercial/third-party proxyware agent installed without consent to monetize victim bandwidth (proxyjacking), including masquerading via a deceptive scheduled task name.
Proxyware payload installed via DPLoader/PowerShell that monetizes victims by sharing their network bandwidth through a proxy service; deployed with persistence via scheduled tasks and accompanied by Defender tampering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.