FILEMembers
FILE

Fake KMS Activator's Broken Signature Feeds a DynDNS Downloader Chain

A pirated KMSoffline activation tool carries a code-signing certificate that fails validation outright, using a publisher name rather than real trust to get past Windows prompts. Beneath it sits a disposable VBScript/JScript downloader stage that beacons to a free DynDNS domain and stages payloads on a two-month-old lure domain — all tagged upstream to APT27 despite no shared technical fingerprint across the set.

Aug 25, 2026, 22:44 (UTC+9)Last seenAug 25, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC26MITRE53RegionsTH

The file at the center of this case doesn't try to hide what it claims to be. It presents itself as KMSoffline, a real, widely pirated Windows-activation utility, and ships inside folder paths named "activador office," "KMSoffline v2.3.5 RU EN," and "KMS Tools Portable 2022" — the exact packaging a user would expect from a torrented activation bundle.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence