Viruses aimed at stealing cryptocurrency were found in official Procolored drivers

Making printers and stealing crypto: what Procolored was really up to

21.05.2025

649

17 min

The Chinese company Procolored became one of the most popular printer manufacturers in its seven years of existence. Their products had a good balance of price and quality. But, it turned out that Procolored was also engaged in illegal activities. GetBlock AML Research tells how the manufacturer got caught in a massive cryptocurrency theft.

Fair name

Procolored started producing printers back in 2018 and quickly conquered the market. The manufacturer mainly focused on fabric printing and produced related products. Until 2024, the company was not seen in any dubious affairs. Its products were exported to 31 countries.

At the end of 2024, owners of Procolored printers encountered problems installing drivers (special software for proper operation of the devices). Antivirus systems identified the drivers as malware and moved them to quarantine. Because of this, users were unable to configure their printers.

Official repository with Procolored drivers on Mega file share

The secret is out

In one of the Reddit threads, a popular YouTube blogger under the nickname Coward reported the problem described above. When buying a new model of Procolored printer, he was unable to install the driver that came on a flash drive with the device. The blogger encountered a similar problem when trying to download the driver from the official Procolored website.

A thorough analysis of the driver showed that it contained 39 infected files with the XRedRAT remote access trojan and the SnipVex clipper, which replaces the copied cryptocurrency address in the clipboard with the kidnappers’ wallet. Drivers for the following Procolored models were infected: F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro.

SnipVex clipper source code in Procolored driver files

Procolored’s response

Following the discovery of viruses in printer drivers, Procolored removed the infected software from their website and announced the launch of an internal investigation. According to the manufacturer’s preliminary version, the malicious files got into the software they were distributing by accident, as the developers’ computers were themselves infected. On the same day, clean versions of the drivers appeared on the manufacturer’s website.

Onchain analysis

One of the attackers’ addresses (1BQZZKqdp2CV3QV5nUEsqSg1ygegLmqRygj) that was found in the infected driver belongs to the US exchange Coinbase, according to Arkham. The wallet was created in 2016 and has accepted 9,3 BTC (almost $1 million at the exchange rate as of May 21, 2025) during its existence. These are mostly small amounts ranging from a few dollars to a few hundred dollars. The address was used as a buffer address. After the cryptocurrency was stolen, it was immediately transferred to other disposable wallets.

The amount of damage caused by Procolored’s actions could be much larger. GetBlock AML Research found over 100 other addresses that were used to store stolen funds. All of these addresses are believed to belong to the Coinbase exchange. The highest activity of malicious wallets was observed in 2022 and 2024.

Addresses associated with criminals

BTC processed

3DzRKF7wGPLJew98pdc8f9h8CbJ8z7UDKt

0,82

3CZ8rGiBYdfsjSuN7nRd53AaTKajgqSmBP

0,67

36s1hPUdtSdyqwJRToC4RQsfbvH3WzGzLm

0,00047

3P4tinANuP5qEc2hFu16yDfX85RC6L6bti

0,0067

3NSCv8AwdBATKnTKd2DRYzoJkpQSf2YKUU

0.0068

3MoRKMk4NzFBtE9AASJsTRkZ7MjJu8tkUJ

2,41

33G3U9L7PLwJLFnBg637wDoLpxinrynMXE

0,15

3AKBFdxHtmzbkg9uMvXoqWbEPERiaR5Y7x

0,035

39P7BPc7q7syVErBYPQY1m8GwNkuQjNiaP

0,004

bc1q0gzmtp3drr6t0jtd2ga30yp9kz65qf72ugsfsm

0,00019

35VVNbjY4erodeThHKEJVm1G64wL2C2Mp6

0,056

bc1qxjf8a6xtph75nfp4xjgasvkd2tuchpd709l07x

0,00023

3BHZyFCZ4DiNwo9WaiuRW78Y9tRAyyTETj

2,25

3K8psz1SP8Zu4cjKAwPqYm2SrXkWFyyk2A

0,01

35o9G7wGoTUisnvxT9NMQnst3qzBD1AVb1

0,051

3FdZZB3Fai5eyM1XvNtaruNtT3Ftct3Gzc

15,9

3HtVN61fT6BydzedM15E6nNib6oJZR1rLh

0,01

36tgunoz8xoKyzMut7CKARVPRoP7CUcP1G

1,1

3FZf4fWCGQmkRFw5dyKu2BPYRKK5vvyiPn

0,056

3LnMCTnsnp4ig2GWEnVk7iCWwRzAiYTN8Z

0,012

bc1qce8qd0hp2e2ur392fsd46j06y5pt2lxa84mfxj

0,00063

bc1qywj7qamu36x7lhcqv7emdq0mlgzfhywfwrqavy

0,055

3NX7ANYxmhwGXn311S3xEVFrXwXvUCL3FC

0,0031

35dAX3SkYNXFftGuvxsKwsaV6UcMRRXXWP

0,031

3MKry7Q2iVjeXxpNce8w8Apxwh1gSPKbBR

0,66

3CMYRD6MURD6yCieD4hBv6dEUtRFLim2Np

6,08

35qdyQ99GgN1EBcbE4jTh5sGfeWPCghvUm

0,048

bc1qrcg06zt63twadj9pqt3ack0k8a7fvyskrv4q9f

0,05

36Z73n1vh29KsPdSPT5nC53QEQ4bTWEiKT

0,084

3C88urnZPcTUXLYcWhKipxQ1DoN3qi6uWQ

0,033

3BazLYCWdctRNwBxi6eDqXWTc1WoJJJEi8

0,014

358D11c3WQJzgFvMGgU7TAigifDoL5ZkMd

0,65

3JGf64uHZx6uSraXAE3oPcNDNkR8qRUJc4

0,021

3QTXoPP26B4AiAXNMKPWczjfs3MXcKT2KX

0,0058

3AU4hdyyhbjMb3k4e6Tf2XhrvUR3JvoFCt

0,037

3QMgu4taqmxrAQUgjhjJJ2E4g1JQvs5YDw

0,00087

34gW9bY3knHWdZrWzmFfMesvnWqgaEUHEY

0,97

38j4DFtvqcxge748PzZ4BVg5ZwCtaA1KK5

0,013

38yJhEGEsmiMDggPcaChNqttgHGoPf7x5m

0,056

3PFn8oijmaAj2wJEeMDJcfNjWafSfMgwDX

0,036

35oWBiQ4BzfT7uCu4FtGgi5ipgYJLpMna2

0,067

3MVkJ3DDqzknFZd6St4yepZm6NUjWmRBrT

25,46

3K7D3tjfz7SMhAWzgJJ5jH5EdUkBoF5dqg

0,013

33r2J86UphwZVVG8sHkshND9UZbNqTq26P

0,081

32ncs79oavGYyWKJMFXDSBBHf57hwtauFj

1,31

37BorSZxNk4Em9t3imWLe2FWtSQd7hoytf

0,0082

3MyVX8eSej5gU7xHP9WEgu2Atjbw846xce

0,013

3NXVnsFo5BKSfwigXjPBvsPsqNu4H3FQCA

0,68

3LE6ogD4GmQTu1tzraopyNmEM48pwRddxd

0,016

3QPYyfV4FEWBLSZUEQRRgUbV7MpdTYGAKv

0,0054

3PUzRBecHw2ApBjmdeEwZ9chrfPe1Tupe7

0,81

3MkrMtm2tUxErhqR5dpBJVCX6kumbXmxub

7,76

3GCA2aTyc7uAoG2gWmAcFnnNaATtLtT9Py

0,2

3LYknffHpreTMQ6FBhkUS5AsWksh17CyYc

0,49

3Q2acaVWsDrRAWCecxZHEdsbipKSrcto3E

0,057

3AJZaZM47imATRys53rrRcQvtUuR6Vj2MG

0,12

3DMshbtVC8HKjkweaY9jFw2SAwEX6HPum3

0,015

36rhwWVG1gkb7oxzxH7aoNPEd6obnprizh

1,2

bc1qhtx253nd34qvx9cy6p3u3q0e84dqj5dl0rnqer

0,14

3DfaT4YqpZPyv3j1s1aDefxSgJqiyoX1Cx

0,2

361WPKJUj8b7HkbG4veLXRjD6XdZi5ZmbZ

4,4

32GeitrAy5wBQ54c3s4K16fFyox6FLm2My

0,013

3KyyiygXKEWdBaM4XJohND7pbnjUsitihq

0,0026

3LuFk4hrfYNRQY3g4wQdPfEACEnRQ2jm6C

0,59

37oYP7yubRD7225oMY4JRAg3yq4r9J5t3a

0,00012

3BKcKpPqgceVMxUuw26dGGxgCpFwfqkD8W

0,00012

32BjXKxVAzXdcxwmXhEroPeq8gJJLXwzCV

0,5

388xkWDMJYdK72QT5qWdrbjzetrSjUPZuZ

3,34

3GiLBsU7iTeDtyFGE1FE4Y94zU32BweG58

10,26

3HSGfxeZjN2CQtmsX1TpzACM6NysBx69AC

5,89

3PoUd9wZd1ZKGzGpZztmHezG2kWEAu7c3v

0,24

354njPbNLvLun6PoqXSqvPziQtzXzzS8pD

2,16

36D9zNtdYxvFjsYCzB4qFpsheGmQ54wCEp

0,055

33R4yCgSYbAa3XeqEH3sSthZopCuxge1xn

0,0072

3PDFAoG4PxQErdsPwCsm9PdV5FEmKeVsas

0,14

3LeVjampgKHb1QV2TvQgmsABG6hVaMNaZj

0,061

3EZAg4SPAmaYW347KCBUvvKtvQxhcrBxTb

0,86

39GeousgLL5F4RiFpCLrf8pm4tUE772TGB

0,00025

37q6yXKoMm9FCQjseB1uJT3FmY1Uvf8sYS

0,12

3AKZRxUjjrLNHMuce7q9pVXngziBT6wuiz

0,0028

3AkEypSbBH8vwdYT4M3eD1GyL3ubgBszyt

0,15

3L6fWqj3gcSq4hFZbtXhjf2nsEvaSBZrZZ

0,002

bc1qjefzc4xxfsdaa0neg2e0a40daahaslzdqwx0el

0,22

3LfyrNSUTynnkwd3gvhGKRQenXHzF3LV8p

5,44

32KZnAqarfbxhMwovUyVhFxF9oS8GmPoma

2,21

37Q7DdGTYncRQsPHtpSgrZyqxwJgPqjRmz

3,74

32y67BcuAUbFpX9VJqqqbKUtrYwQ2pUFtJ

0,0047

35Y9tSMauCkyvZz1r79HNohUHUxuqx9vSG

23,71

345jki5dohV86eZQJDQzi3iaEbK9rko9wm

0,17

3KBC4dzyWmrkuWgAgUF75fo1cXk8gprmQY

0,015

3F3LbEkErKxsD6vRMwGQr6wKzuFJN2VAoy

0,0017

3MbViAVUah3D299fc9pQsD1oqajMyQ4MaJ

0,024

3NyfjtNiWiWpYVhFYR9DZCR1nnktwXQjwP

0,0033

323fRqNSvvsfa6KMqnDNgyHf1RRQjdDcXJ

0,014

3KrZyx4gZPvWDnMwJCzJVTQuKL49pvLM3V

0,68

3Hfj4QZiaDW32o9zduwu3ALh3drXx5Y48U

0,51

35ycXtFRD9TYVnnpvBdZjq6AS1P5u3KPMc

2,29

3CUWicnKmm41GD82kNBbAzLxYPSwxdktW4

0,044

335U7KBvcH5fiGZA8bvA7zggi5TRLn8gcg

0,015

3QsCn1yZJQnGoA1UU59rGPSp1ZHkpbss6p

0,021

38Q3BJSqwXebDjp4ftgReX9BTJdEWQ1L1s

0,00022

3FBmFR6MhWgMeR1BG1c1qjcfqz3S3jhyuK

0,004

3Crx1uSxmrsquX4kY1kBK6ipjVJWReLAmB

0,23

Total

139,17 ($14,8 million)

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy