FILEMembers
FILE

Pirated Windows Activator Bundle Hides Shared Base64 Execution Trick

A file cluster tagged with the TA505/rockloader label turns out, on close inspection, to be a pirated 'Microsoft Activation Scripts' KMS/Office activator toolkit. Two of its components independently trigger the same base64-decode-and-execute YARA rule despite being different file types, while two others share a suspicious .win-TLD DNS callback.

Aug 5, 2026, 11:49 (UTC+9)Last seenAug 5, 2026Severity65ByCTX TeamActorTA505Hive0065IOC11MITRE13

A "Microsoft Activation Scripts" archive built to bypass Windows and Office licensing is now doubling as a delivery mechanism for base64-encoded PowerShell payloads — and the same authoring fingerprint shows up in two structurally different file types inside the same drop. Eight of nine files tied to this indicator set carry file paths referencing "MAS/Separate-Files-Version" or "MAS/All-In-One-Version-KL," all first appearing within a 48-hour window between July 4 and July 6, 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence