Hackers are covertly turning compromised Windows and Mac computers into proxy servers and are monetizing this proxy service, according to AT&T’s Alien Labs.
In a report on Wednesday, August 16, Alien Labs said different malware strains, delivered through pirated software, games, and other “alluring offers,” are used to infect devices and install proxy server applications.
“The application is silently installed by malware on infected machines without user knowledge and interaction,” Alien Labs said, adding that the proxy application slips past antivirus scanners undetected.
The Alien Labs team observed over a thousand new malware samples spreading the proxy application in just one week.
Over 400,000 Proxy Exit Nodes
The company responsible for this proxy service alleges that it operates over 400,000 proxy exit nodes. The number of these nodes created through malware remains unclear.
When installed on a device, the proxy application routes traffic from unknown sources and “continuously gathers” information about the infected device. “This includes everything from process list and monitoring CPU to memory utilization and even tracking battery status. This dynamic data collection underscores its capability to manage the demands of proxy requests while evading suspicion by adapting to the system’s operational context,” Alien Labs’ report said.
The proxy application also checks for new updates “on hourly basis.”
The threat actors behind this campaign have an affiliate program, which “creates a formal structure to increase the speed at which this threat will spread,” the researchers warned.
On Thursday, August 10, Alien Labs researchers reported that threat actors are using the AdLoad malware to transform Mac devices into proxy exit nodes. The latest report highlights how the campaign also targets Windows devices.
“In the constantly changing world of cyber threats, the intertwined relationship between innovation and malicious intent propels new strategies by nefarious actors,” the researchers said, highlighting the need to remain “vigilant and adaptive” to combat evolving threats.
How to Delete This Malicious Proxy App
If your device has been infected by this malicious proxy application named DigitalPulse, AT&T Alien Labs recommends deleting particular folders, registry entries, and scheduled tasks associated with the malware.
To remove the software, delete the “DigitalPulse” folder in %AppData%. Next, remove the “DigitalPulse” entry from the Windows Registry at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ and disable the “DigitalPulseUpdateTask” in the Task Scheduler. Always exercise caution when modifying your device’s registry. It’s advisable to make a registry backup first.
We recommend that you avoid downloading apps from unverified sources as they could be embedded with malware. It’s important to only download apps from trusted sources and official app stores. We recommend using a premium antivirus program to scan your device regularly, especially after installing new software. While antivirus scanners didn’t detect this malware, they can detect most malware.
