FILEMembers
FILE

Trojanized CorelDraw Crack Hits Brazil With Four-Payload Attack Chain

A pirated CorelDraw activation archive circulating since March 2025 has reached 887 unique submitters and is deploying PureLogs credential theft, a coin-miner, hosts-file poisoning, and a BYOVD kernel driver against Brazilian construction, hospitality, media, and retail targets. The campaign's operational depth includes a single .NET build pipeline producing three functionally distinct payloads, PE timestamps forged to 2082 and 2092, and a Cloudflare-proxied C2 architecture backed by a geographically separated fallback node.

Jun 12, 2026, 03:25 (UTC+9)Last seenJun 12, 2026Severity100ByCTX TeamIOC26MITRE72RegionsBR

A trojanized CorelDraw activation archive that has reached 887 unique submitters since March 2025 is deploying a layered attack chain against Brazil's construction, hospitality, media, and retail sectors — one that combines a PureLogs credential stealer, an embedded coin-miner, a three-stage hosts-file poisoning sequence, and a Bring Your Own Vulnerable Driver (BYOVD) component borrowed from a 2008-era kernel driver.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence