{
  "slug": "trojan-proxy",
  "name": "Trojan (Proxy)",
  "description": "A sophisticated multi-platform malware distributed through illegally cracked software, designed to transform compromised devices (macOS, Android, Windows) into nodes of a proxy server network. Attackers leverage these proxy networks for financial gain or to conduct further illicit activities, utilizing stealthy communication techniques like DNS-over-HTTPS (DoH) to evade detection. The malware infiltrates systems by replacing legitimate files and establishing persistence.",
  "url": "https://optimly.ai/brand/trojan-proxy",
  "websiteUrl": null,
  "logoUrl": "https://logo.clearbit.com/securelist.com",
  "baiScore": 54,
  "bai_tier_status": "active",
  "bai_score_status": "active",
  "archetype": "Phantom",
  "archetype_status": "active",
  "category": "Cybersecurity Threat",
  "categorySlug": null,
  "keyFacts": [],
  "aiReadiness": [],
  "competitors": [],
  "competitorsProse": null,
  "inboundCompetitors": [],
  "aiAlternatives": [],
  "parentBrand": null,
  "subBrands": [],
  "updatedAt": "2026-08-09T00:01:59.124Z",
  "verifiedVitals": {
    "website": "https://securelist.com",
    "founded": "2023",
    "pricing_model": "N/A (malware, often 'free' to the victim but profitable for attackers)",
    "core_products": "Not a product; its core function is to facilitate illicit proxy networks and criminal activities.",
    "key_differentiator": "Its distribution method via .PKG installers for cracked macOS applications and use of DNS-over-HTTPS (DoH) for discreet C&C communication, combined with multi-platform targeting, distinguishes it.",
    "target_markets": "Users seeking free, cracked software on macOS, Android, and Windows.",
    "employee_count": "N/A",
    "funding_stage": "N/A",
    "subcategory": "Malware, Trojan, Proxy Malware"
  },
  "intentTags": {
    "problemIntents": [
      "Manual botnet/proxy setup: Attackers manually compromise machines and configure proxy services without relying on specialized, automated Trojan-Proxy malware.",
      "Cybercrime-as-a-Service (Proxy Botnets): Criminals could purchase access to existing proxy botnets or 'rent' compromised IP addresses from other cybercrime groups, rather than developing and distribut"
    ],
    "solutionIntents": [
      "Trojan Proxy malware",
      "WindowServer macos malware",
      "cracked software proxy malware",
      "Securelist Trojan Proxy analysis",
      "Commercial VPN/Proxy Services (abused): Attackers could abuse legitimate or dark-market VPN/proxy services, which might offer more anonymity and infrastructure at a cost, bypassing the need to build t"
    ],
    "evaluationIntents": []
  },
  "timestamp": 1786384523013
}