Description
Floxif is a worm that spreads through network shares and infected removable drives, and it rose to prominence as the payload hidden inside the compromised CCleaner application in 2017. The trojan collects system information and downloads additional payloads from remote servers, and its presence in a widely distributed, digitally signed utility demonstrated how supply chain compromises can reach millions of machines. Detections under this name indicate worm behavior that propagates through shared storage.
Stats
- First seen
- January 2022
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| Win32.Floxif.A |
| Win32.Floxif.Dam |
| Win32.Trojan.Floxif |
| Win32.Virus.Floxif |