FILEMembers
FILE

Fake Root CA Signs Pirated KMS Activation Tools

Four KMSpico/AutoKMS crack files share an identical, self-manufactured '@ByELDI' certificate chain that fails Windows' own trust validation. An imphash-identical trio and shared obfuscation and anti-analysis code point to one build pipeline behind the whole bundle.

Aug 9, 2026, 01:56 (UTC+9)Last seenAug 9, 2026Severity44ByCTX TeamActorPatchworkChinastratsIOC17MITRE51

Four Windows activation cracks distributed under the KMSpico and AutoKMS names carry an identical code-signing chain — but the authority that issued it isn't Sectigo, DigiCert, or any of the trust roots Windows ships with. It's "@ByELDI Certificate Authority," a self-manufactured root the operators built themselves, and every certificate under it fails Windows' own validation check.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence