
Fake KMS Activator's Broken Signature Feeds a DynDNS Downloader Chain
A pirated KMSoffline activation tool carries a code-signing certificate that fails validation outright, using a publisher name rather than real trust to get past Windows prompts. Beneath it sits a disposable VBScript/JScript downloader stage that beacons to a free DynDNS domain and stages payloads on a two-month-old lure domain — all tagged upstream to APT27 despite no shared technical fingerprint across the set.
The file at the center of this case doesn't try to hide what it claims to be. It presents itself as KMSoffline, a real, widely pirated Windows-activation utility, and ships inside folder paths named "activador office," "KMSoffline v2.3.5 RU EN," and "KMS Tools Portable 2022" — the exact packaging a user would expect from a torrented activation bundle.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read