Floxif
- First seen
- 2017-08-01 00:00:00
- Malware type
- downloader, dropper
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:27:55
- Profile updated
- 2026-07-07 14:51:50
Context
Floxif is a malware primarily known for being involved in supply chain attacks, where it was used to download additional malicious payloads. It gained notoriety for its role in the 2017 CCleaner compromise, where it was embedded in a legitimate software update.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Floxif_Auto (yara-rule)
Reports & references
- Mandiant — Pe File Infecting Malware Ot (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Floxif (report)
- virusbulletin.com — Compromised Library (report)