APTMembers
APT

Fake KMS Activators Share One Untrusted Signing Certificate

Two cracked-software installers — a KMSAuto++ activator and a fake Office C2R installer — share an identical, untrusted WZTeam code-signing certificate and UPX packing, chaining into a sandbox-confirmed PowerShell downloader stage. An APT27 and njRAT tag rides atop the record despite the concrete evidence pointing to commodity pirated-software tradecraft.

Jun 14, 2026, 02:14 (UTC+9)Last seenJul 2, 2026Severity62ByCTX TeamActorAPT27TEMP.HippoIOC20MITRE53RegionsTH

Two Windows executables masquerading as pirated-software tools — one branded "KMSAuto++.exe," the other disguised as an "Office 2013-2021 C2R Install Lite" installer — are circulating with an identical, untrusted code-signing certificate stamped by an entity calling itself WZTeam. The certificate, serial 8A C1 A3 10 13 49 C2 8A 4D 33 94 7C FC D0 76 62, terminates in a root that Windows does not trust, yet it appears verbatim across both binaries, alongside a shared VirusTotal family label of…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence