Friday, August 28, 2026

Printer Company Distributes Malicious Drivers Infected with XRed Malware

Procolored, a printer manufacturing company, has been found distributing software drivers infected with malicious code, including the notorious XRed backdoor malware.

The issue came to light when Cameron Coward, a YouTuber behind the channel Serial Hobbyism, attempted to review a $6,000 UV printer and encountered antivirus alerts upon plugging in a USB drive containing the printer software.

The alerts flagged a USB-spreading worm and a Floxif infection, a severe file infector known for attaching itself to Portable Executable files and spreading across network shares and removable drives.

This incident prompted an in-depth investigation into Procolored’s publicly available software downloads, hosted on mega.nz for six printer models, revealing a widespread malware distribution affecting 39 files, 20 of which had unique hashes.

Uncovering a Serious Security Breach

A detailed analysis of the infected files identified two primary threats: Win32.Backdoor.XRedRAT.A, a Delphi-based backdoor previously documented by eSentire in February 2024, and MSIL.Trojan-Stealer.CoinStealer.H, a .NET-based clipbanker dubbed SnipVex.

XRed Malware
Malcat shows XRed version 106 in the RCDATA/EXEVSNX resource

The XRed backdoor, present in files like PrintExp.exe (SHA256: 531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434), facilitates keylogging, file downloads, screenshots, and remote command execution via a cmd.exe shell.

Interestingly, its command-and-control servers have been offline since early 2024, limiting active remote exploitation risks.

However, the SnipVex virus, a prepending file infector, poses a persistent threat by targeting .exe files across logical drives, replacing Bitcoin addresses in the clipboard to divert transactions to the attacker’s wallet, which blockchain records show accumulated approximately $100,000.

SnipVex’s infection mechanism includes an infection marker (0x0A 0x0B 0x0C) to prevent superinfection and avoids system directories like %TEMP%, but its presence in legitimate software bundles suggests negligence in Procolored’s build or distribution systems, likely due to absent or failed antivirus scanning.

Malware Details and Potential Impact

Procolored initially dismissed the antivirus alerts as false positives but removed the downloads from their website around May 8, 2025, after persistent concerns.

Upon being provided with detailed malware analysis, the company acknowledged the possibility of infection during USB-based software transfers and committed to rigorous security checks before re-uploading files.

XRed Malware
Procolored.com website

They have since provided clean software packages to affected users and issued guidance for customers to revoke any antivirus exclusions set for their software.

For those potentially infected, experts recommend a full system reformat and OS reinstallation due to the irreversible damage caused by file infectors like SnipVex, though original files may be recoverable by truncating the virus payload in non-superinfected instances.

According to the Report, this case underscores the critical need for robust security practices in software distribution, especially for hardware vendors whose products are trusted by consumers.

While speculation about intentional malware planting exists, the outdated nature of XRed and the inactive C2 infrastructure suggest accidental contamination over malice.

Procolored’s ongoing efforts to remediate the issue are a step forward, but the incident serves as a cautionary tale for users to remain vigilant about software sources, even from official vendors.

Indicators of Compromise (IoCs)

MalwareTypeIdentifier
XRed BackdoorSHA256531d08606455898408672d88513b8a1ac284fdf1fe011019770801b7b46d5434
SnipVex VirusSHA25639df537aaefb0aa31019d053a61fabf93ba5f8f3934ad0d543cde6db1e8b35d1
SnipVex BTC WalletAddress1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj
SnipVex Run KeysRegistry PathHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ScdBcd, ClpBtcn

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value...

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including...

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can...

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed...

Related Articles

Recent News