# Trojan (Proxy) > A sophisticated multi-platform malware distributed through illegally cracked software, designed to transform compromised devices (macOS, Android, Windows) into nodes of a proxy server network. Attackers leverage these proxy networks for financial gain or to conduct further illicit activities, utilizing stealthy communication techniques like DNS-over-HTTPS (DoH) to evade detection. The malware infiltrates systems by replacing legitimate files and establishing persistence. - URL: https://optimly.ai/brand/trojan-proxy - Logo: https://logo.clearbit.com/securelist.com - Slug: trojan-proxy - BAI Score: 54/100 - Archetype: Phantom - Category: Cybersecurity Threat - Last Analyzed: August 9, 2026 ## Buyer Intent Signals Problems: Manual botnet/proxy setup: Attackers manually compromise machines and configure proxy services without relying on specialized, automated Trojan-Proxy malware. | Cybercrime-as-a-Service (Proxy Botnets): Criminals could purchase access to existing proxy botnets or 'rent' compromised IP addresses from other cybercrime groups, rather than developing and distribut Solutions: Trojan Proxy malware | WindowServer macos malware | cracked software proxy malware | Securelist Trojan Proxy analysis | Commercial VPN/Proxy Services (abused): Attackers could abuse legitimate or dark-market VPN/proxy services, which might offer more anonymity and infrastructure at a cost, bypassing the need to build t