Larva-25012 has resumed a proxyjacking campaign that abuses DPLoader infections already present on compromised Windows systems, with numerous victims reported in South Korea. The loader profiles hosts, communicates with command-and-control infrastructure, executes PowerShell-delivered payloads, and creates Windows Scheduled Tasks for persistence before installing proxyware from DigitalPulse, SOAX, Appsalt, and IPRoyal. These tools monetize victims’ internet bandwidth without their consent.
The operators disguise executables, DLLs, installation paths, and scheduled-task names as legitimate Windows or Microsoft components. DPLoader retrieves payloads from Cloudflare R2 and CloudFront-hosted URLs, reports data to an AWS Lambda endpoint, and was observed disabling Microsoft Defender in DigitalPulse deployments. Organizations should investigate existing DPLoader infections, review suspicious scheduled tasks and PowerShell activity, and block the campaign’s identified hosting and C2 indicators.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC published a technical analysis documenting the DPLoader-enabled proxyjacking campaign, including payload infrastructure, persistence tasks, file paths, command-and-control endpoints, and file-hash indicators.
The resumed campaign used PowerShell-delivered installers to deploy multiple proxyware services, with loaders supplying attacker-controlled SDK tokens. The payloads used masquerading filenames and scheduled tasks for persistence; the DigitalPulse installer also attempted to disable Microsoft Defender.
In the second half of 2026, Larva-25012 resumed active proxyware distribution, primarily abusing DPLoader instances already installed on compromised systems. The activity targeted numerous systems in South Korea and used DPLoader to collect host data, maintain scheduled-task persistence, receive C2 commands, and run PowerShell installers.
The group distributed proxyware through pages offering illegal software cracks, extending its use of deceptive delivery channels.
Larva-25012 was active in distributing proxyware from at least 2025, initially using deceptive channels including pop-up advertisements on free YouTube-download sites and a GitHub repository posing as a Steam cleanup tool.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.