
Fake KMS Activators Share One Untrusted Signing Certificate
Two cracked-software installers — a KMSAuto++ activator and a fake Office C2R installer — share an identical, untrusted WZTeam code-signing certificate and UPX packing, chaining into a sandbox-confirmed PowerShell downloader stage. An APT27 and njRAT tag rides atop the record despite the concrete evidence pointing to commodity pirated-software tradecraft.
Two Windows executables masquerading as pirated-software tools — one branded "KMSAuto++.exe," the other disguised as an "Office 2013-2021 C2R Install Lite" installer — are circulating with an identical, untrusted code-signing certificate stamped by an entity calling itself WZTeam. The certificate, serial 8A C1 A3 10 13 49 C2 8A 4D 33 94 7C FC D0 76 62, terminates in a root that Windows does not trust, yet it appears verbatim across both binaries, alongside a shared VirusTotal family label of…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read