Floxif

First seen
2017-08-01 00:00:00
Malware type
downloader, dropper
Family
Malware family
Last IoC activity
2026-07-22 02:27:55
Profile updated
2026-07-07 14:51:50

Context

Floxif is a malware primarily known for being involved in supply chain attacks, where it was used to download additional malicious payloads. It gained notoriety for its role in the 2017 CCleaner compromise, where it was embedded in a legitimate software update.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Floxif_Auto (yara-rule)

Reports & references

  • Mandiant — Pe File Infecting Malware Ot (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Floxif (report)
  • virusbulletin.com — Compromised Library (report)

External references