Netskope Threat Labs

Floxif

ATP Sandbox Adv. HeuristicsAV

Floxif is a worm that spreads through network shares and infected removable drives, and it rose to prominence as the payload hidden inside the compromised CCleaner application in 2017. The trojan collects system information and downloads additional payloads from remote servers, and its presence in a widely distributed, digitally signed utility demonstrated how supply chain compromises can reach millions of machines. Detections under this name indicate worm behavior that propagates through shared storage.

First seen
January 2022
Last seen
September 2026
Alert Name
Win32.Floxif.A
Win32.Floxif.Dam
Win32.Trojan.Floxif
Win32.Virus.Floxif