
Reused Certificate Ties Two KMS Activators to One Build Pipeline
A 32-bit and 64-bit KMSAuto++ activator pair share a byte-identical, chain-invalid WZTeam code-signing certificate, proving they came from a single build run rather than separate operators. Both binaries are UPX-packed and carry the same Defender-disabling registry payload, distributed via a disposable domain mimicking a piracy download site.
A pair of Windows licensing-bypass tools carrying an identical, cryptographically dead-end code-signing certificate has surfaced in a four-file cluster enriched for this feed — and the certificate is the strongest piece of evidence in the whole set. The x86 build, hashing to 50b277f770648c014924c5bf17ed94bfe149ec317a4f8b70129f3dd76e0d0a64, and its x64 counterpart, 3f2e66bbb2ed7be8655c258a2e0e43fb5bba482ae909c2c2e91865699d33b6bf, both carry a signature block naming "WZTeam" as signer, with a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read