IPRoyal is commercial residential proxyware abused in financially motivated proxyjacking campaigns. It registers participating devices with the IPRoyal proxy network and monetizes their Internet bandwidth and IP addresses by routing third-party traffic through them. Unauthorized installations allow attackers to profit from compromised systems without the owners’ consent; this abuse does not make every installation of the legitimate service malicious.
IPRoyal has been deployed on compromised Linux systems in the LABRAT operation and by Mimo, also known as Hezb. LABRAT exploited GitLab vulnerability CVE-2021-22205, while Mimo exploited Craft CMS vulnerability CVE-2025-32432 and used a Go-based loader to install IPRoyal alongside XMRig. These operations combined bandwidth monetization with cryptomining.
On Windows, Larva-25012 has deployed IPRoyal through DPLoader in proxyjacking activity primarily targeting South Korea. The installation uses a loader and an IPRoyal SDK DLL, establishes persistence through Windows Scheduled Tasks, and disguises components using Microsoft-like naming and directory structures. The group’s proxyware distribution has included advertising pop-ups on freeware download websites, deceptive utility lures, and software-crack download pages. Credential theft, mining, and remote-shell functionality are not established capabilities of IPRoyal itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IPRoyal est installé avec un chargeur et la DLL SDK pawns-sdk.dll, une tâche BackgroundTaskRegistrationMaintenanceTaskScheduler et un chemin imitant Microsoft\TaskRegistrationMaintenanceTask.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxyware distribué pour détourner et revendre la bande passante des hôtes compromis; il est installé avec un chargeur et une DLL SDK, et maintient sa présence avec une tâche planifiée déguisée.
Proxyware deployed with a loader and SDK DLL that consumes the victim host’s network bandwidth for actor profit; it persists through a scheduled task.
IPRoyal is used as residential proxyware on compromised hosts, registering the victim device to monetize its bandwidth and residential IP connectivity for the attacker’s benefit.
Legitimate proxyware abused on compromised systems to monetize victims' internet bandwidth and IP addresses. The operation stored an associated binary, rcu_tr, in its private GitLab repository.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.