AT&T Alien Labs Uncovers Expansive Campaign: Windows Machines Ensnared in Proxy
thefinalhop.com
thefinalhop.com
ProxyNation: The dark nexus between proxy apps and malware
https://cybersecurity.att.com/blogs/labs-research/proxynatio...
Which means it should be easy to wipe out with the next MSRT/Windows update. Considering unpacking Inno and decompiling that weird Pascal(?) scripting it uses has been a thing forever now (innounp). Meaning you can also fully reverse engineer this with a single CLI command and Notepad++ lol
Although this is super clever. I'll give them that.