Author Topic: US$ 6k UV printer came with backdoor and trojan  (Read 2407 times)

0 Members and 1 Guest are viewing this topic.

Offline madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 8994
  • Country: de
  • A qualified hobbyist ;)
US$ 6k UV printer came with backdoor and trojan
« on: May 19, 2025, 01:11:56 pm »
A review of the Procolored V11 Pro changed into hunting down malware in the driver:
- The Maker’s Toolbox: Procolored V11 Pro DTO UV Printer Review, https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3
- Viruses included in product I'm reviewing?, https://www.reddit.com/r/computerviruses/comments/1kbkmgq/viruses_included_in_product_im_reviewing/
- Printer company provided infected software downloads for half a year, https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads

TL;DR:
- driver for UV printer came with backdoor and trojan for at least half a year
- manufacturer denies allegation
- security company confirms malware
- manufacturer comes up with lame excuse and uploads new driver
 
The following users thanked this post: Kean, RoGeorge

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 17553
  • Country: fr
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #1 on: May 19, 2025, 02:24:11 pm »
Was it intentional or the result of having outsourced development? :popcorn:
 

Offline madiresTopic starter

  • Super Contributor
  • ***
  • Posts: 8994
  • Country: de
  • A qualified hobbyist ;)
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #2 on: May 19, 2025, 04:38:05 pm »
I'd guess the manufacturer won't tell us that.
 

Offline eutectique

  • Frequent Contributor
  • **
  • Posts: 611
  • Country: be
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #3 on: May 19, 2025, 04:47:08 pm »
Quote
It is also worth noting that I contacted Procolored support four times over the course of my testing, for help with figuring out the software and settings. Every single time, the agent requested multiple times that I allow them to connect remotely to my computer. Obviously, I declined every time. But I want to note that they kept asking. Do with that information what you will.

This is fishy.
 

Offline RoGeorge

  • Super Contributor
  • ***
  • Posts: 8229
  • Country: ro
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #4 on: May 19, 2025, 04:55:54 pm »
...
TL;DR:
- driver for UV printer came with backdoor and trojan for at least half a year
- manufacturer denies allegation
- security company confirms malware
- manufacturer comes up with lame excuse and uploads new driver

Thanks, very good idea to add a brief!  :-+

Offline D.Burnette

  • Contributor
  • Posts: 13
  • Country: us
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #5 on: May 19, 2025, 10:14:36 pm »
It looks like they are built around Epson printheads. So they are at least partially leveraging known-good codebases. Chances are they grabbed a library with crap in it.

Doesn't surprise me that one of the cheaper DTF/UV printers on the market has badly written drivers with embedded malware...But their "address" is on their website if you want to head to Los Angeles and bang on the door of a little rented space in an industrial strip.

It seems like they sell in Europe. Luckily in a year or so, the CRA will be enforced. Even people outside of Europe will be able to take advantage of this as a forcing function: Manufacturer doesn't respond? Report the vulnerability to the ENISA, and the manufacturer may have to stop EU sales.
 

Offline UnijunctionTransistor

  • Frequent Contributor
  • **
  • Posts: 454
  • Country: us
  • Ohms Law: Resistance is futile.
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #6 on: May 19, 2025, 10:46:50 pm »
But their "address" is on their website if you want to head to Los Angeles and bang on the door of a little rented space in an industrial strip.



Exactly. Behind the tree.
 

Offline thm_w

  • Super Contributor
  • ***
  • Posts: 9550
  • Country: ca
  • Non-expert
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #7 on: May 21, 2025, 08:45:48 pm »
Quote
It is also worth noting that I contacted Procolored support four times over the course of my testing, for help with figuring out the software and settings. Every single time, the agent requested multiple times that I allow them to connect remotely to my computer. Obviously, I declined every time. But I want to note that they kept asking. Do with that information what you will.

This is fishy.

Could be, but its also normal because it allows support to actually verify your settings.
Customer might say 100 times "yes I set that setting to xyz" then you check on their machine and no, it wasn't set.. So can save time to just do it for them, instead of guiding them over the phone.
Profile -> Modify profile -> Look and Layout ->  Don't show users' signatures
 

Offline ZGoode

  • Frequent Contributor
  • **
  • Posts: 307
  • Country: us
  • Grad student by day, equipment nerd also by day
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #8 on: May 21, 2025, 08:53:53 pm »
Yeah, but a screengrab could suffice here.  The only time I've ever had anyone request remote computer access is at work when the IT center needs to enter the admin password cause none of us are trusted with that.
 

Online langwadt

  • Super Contributor
  • ***
  • Posts: 5643
  • Country: dk
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #9 on: May 21, 2025, 10:29:46 pm »
Report the vulnerability to the ENISA, and the manufacturer may have to stop EU sales.

think that'll work any better that all the safety standards preventing dangerous USB chargers and such being sold?
 
The following users thanked this post: amyk

Offline peter-h

  • Super Contributor
  • ***
  • Posts: 5830
  • Country: gb
  • Doing electronics since the 1960s...
Re: US$ 6k UV printer came with backdoor and trojan
« Reply #10 on: June 05, 2025, 06:16:30 am »
Quote
the agent requested multiple times that I allow them to connect remotely to my computer. Obviously, I declined every time. But I want to note that they kept asking. Do with that information what you will.

That is indeed fishy, but so many vendors are doing it nowadays. Even Google (adwords) is doing it - requesting admin access to our PCs for setting up keywords on our online shop. I refuse and they just say they can't help us at all.

Many years ago, a client of mine sent out a 3.5% floppy disk which was allegedly infected with a boot sector virus (DOS days) and his customer sued him. It was settled but if you get the wrong person it can get tricky ;)
Z80 Z180 Z280 Z8 S8 8031 8051 H8/300 H8/500 80x86 90S1200 32F417
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf