
One Fake Certificate Signs 13 Pirated Windows Activation Tools
Thirteen crack-tool binaries branded as AAct, KMSAuto Net, MSAct++ and others all share a single self-issued 'WZTeam' certificate that fails validation on every sample. Feed labels tie the batch to APT27 and icedid/blackworm, but none of the 20 enriched files' actual VirusTotal labels support that attribution.
Thirteen Windows binaries marketed under a dozen different brand names — AAct, KMSAuto Net, MSAct++, PIDKey Lite, KMSCleaner — all carry the identical self-issued code-signing certificate from an entity calling itself "WZTeam," serial E5 FA 25 47 0F 85 17 BF 41 52 87 01 4D AA 57 8C, thumbprint 87B3A6C360B37D6DB7F970DD1DC0009FBBD13BA0.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read