Making printers and stealing crypto: what Procolored was really up to
Viruses aimed at stealing cryptocurrency were found in official Procolored drivers
21.05.2025
650
17 min
0
The Chinese company Procolored became one of the most popular printer manufacturers in its seven years of existence. Their products had a good balance of price and quality. But, it turned out that Procolored was also engaged in illegal activities. GetBlock AML Research tells how the manufacturer got caught in a massive cryptocurrency theft.
Fair name
Procolored started producing printers back in 2018 and quickly conquered the market. The manufacturer mainly focused on fabric printing and produced related products. Until 2024, the company was not seen in any dubious affairs. Its products were exported to 31 countries.
At the end of 2024, owners of Procolored printers encountered problems installing drivers (special software for proper operation of the devices). Antivirus systems identified the drivers as malware and moved them to quarantine. Because of this, users were unable to configure their printers.
Official repository with Procolored drivers on Mega file share
The secret is out
In one of the Reddit threads, a popular YouTube blogger under the nickname Coward reported the problem described above. When buying a new model of Procolored printer, he was unable to install the driver that came on a flash drive with the device. The blogger encountered a similar problem when trying to download the driver from the official Procolored website.
A thorough analysis of the driver showed that it contained 39 infected files with the XRedRAT remote access trojan and the SnipVex clipper, which replaces the copied cryptocurrency address in the clipboard with the kidnappers’ wallet. Drivers for the following Procolored models were infected: F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro.
SnipVex clipper source code in Procolored driver files
Procolored’s response
Following the discovery of viruses in printer drivers, Procolored removed the infected software from their website and announced the launch of an internal investigation. According to the manufacturer’s preliminary version, the malicious files got into the software they were distributing by accident, as the developers’ computers were themselves infected. On the same day, clean versions of the drivers appeared on the manufacturer’s website.
Onchain analysis
One of the attackers’ addresses (1BQZZKqdp2CV3QV5nUEsqSg1ygegLmqRygj) that was found in the infected driver belongs to the US exchange Coinbase, according to Arkham. The wallet was created in 2016 and has accepted 9,3 BTC (almost $1 million at the exchange rate as of May 21, 2025) during its existence. These are mostly small amounts ranging from a few dollars to a few hundred dollars. The address was used as a buffer address. After the cryptocurrency was stolen, it was immediately transferred to other disposable wallets.
The amount of damage caused by Procolored’s actions could be much larger. GetBlock AML Research found over 100 other addresses that were used to store stolen funds. All of these addresses are believed to belong to the Coinbase exchange. The highest activity of malicious wallets was observed in 2022 and 2024.
|
Addresses associated with criminals |
BTC processed |
|
0,82 |
|
|
0,67 |
|
|
0,00047 |
|
|
0,0067 |
|
|
0.0068 |
|
|
2,41 |
|
|
0,15 |
|
|
0,035 |
|
|
0,004 |
|
|
0,00019 |
|
|
0,056 |
|
|
0,00023 |
|
|
2,25 |
|
|
0,01 |
|
|
0,051 |
|
|
15,9 |
|
|
0,01 |
|
|
1,1 |
|
|
0,056 |
|
|
0,012 |
|
|
0,00063 |
|
|
0,055 |
|
|
0,0031 |
|
|
0,031 |
|
|
0,66 |
|
|
6,08 |
|
|
0,048 |
|
|
0,05 |
|
|
0,084 |
|
|
0,033 |
|
|
0,014 |
|
|
0,65 |
|
|
0,021 |
|
|
0,0058 |
|
|
0,037 |
|
|
0,00087 |
|
|
0,97 |
|
|
0,013 |
|
|
0,056 |
|
|
0,036 |
|
|
0,067 |
|
|
25,46 |
|
|
0,013 |
|
|
0,081 |
|
|
1,31 |
|
|
0,0082 |
|
|
0,013 |
|
|
0,68 |
|
|
0,016 |
|
|
0,0054 |
|
|
0,81 |
|
|
7,76 |
|
|
0,2 |
|
|
0,49 |
|
|
0,057 |
|
|
0,12 |
|
|
0,015 |
|
|
1,2 |
|
|
0,14 |
|
|
0,2 |
|
|
4,4 |
|
|
0,013 |
|
|
0,0026 |
|
|
0,59 |
|
|
0,00012 |
|
|
0,00012 |
|
|
0,5 |
|
|
3,34 |
|
|
10,26 |
|
|
5,89 |
|
|
0,24 |
|
|
2,16 |
|
|
0,055 |
|
|
0,0072 |
|
|
0,14 |
|
|
0,061 |
|
|
0,86 |
|
|
0,00025 |
|
|
0,12 |
|
|
0,0028 |
|
|
0,15 |
|
|
0,002 |
|
|
0,22 |
|
|
5,44 |
|
|
2,21 |
|
|
3,74 |
|
|
0,0047 |
|
|
23,71 |
|
|
0,17 |
|
|
0,015 |
|
|
0,0017 |
|
|
0,024 |
|
|
0,0033 |
|
|
0,014 |
|
|
0,68 |
|
|
0,51 |
|
|
2,29 |
|
|
0,044 |
|
|
0,015 |
|
|
0,021 |
|
|
0,00022 |
|
|
0,004 |
|
|
0,23 |
|
|
Total |
139,17 ($14,8 million) |
Useful material?
Research
A financial system is already up and running on public blockchains, with loans, analogues of U.S. Treasuries, and automated capital markets. More than $551 billion has flowed through DeFi protocols — but most of that activity has nothing to do with the real economy and everything to do with the speculative build-up of risk.
May 29, 2026
Research
Around 97% of Chinese suppliers of chemicals used to make fentanyl accept payment in cryptocurrency. The volume of such transactions continues to grow alongside the global market for synthetic drugs
May 22, 2026
Research
For the first time, the new law makes blockchain analytics an officially mandatory tool of financial oversight in the United States. Authorities will also gain the power to restrict transactions with foreign crypto services tied to money-laundering risks.
May 20, 2026
Research
Working with cryptocurrencies requires more than just new technology — it demands a complete overhaul of internal processes. We explain how the financial sector is learning to control digital assets and detect threats
May 8, 2026
Research
The scammers attempted to conceal over $90 million through complex cryptocurrency transactions. However, part of the funds was successfully traced and frozen.
May 6, 2026
Research
Just two attacks accounted for 76% of all crypto losses in 2026 and generated hundreds of millions in profit for hackers. Here’s how North Korea executes some of the most sophisticated and precise attacks in the industry.
May 1, 2026
Telegram
Twitter