APTMembers
APT

KMS Crack Tool's Twin Binaries Hide Defender-Killer, Konni YARA Hits

Two architecture variants of a pirated Windows activation tool share an identical vhash and the same untrusted-root code-signing certificate, while both embed a Defender-disabling registry routine. A Konni malware YARA hit and a WinDivert driver flag sit atop an otherwise clean sandbox verdict.

Jul 28, 2026, 21:35 (UTC+9)Last seenJul 28, 2026Severity62ByCTX TeamActorGamaredon GroupCTIGIOC7MITRE36RegionsARBRCICODE

Two Windows binaries branded as a routine Microsoft-activation "crack" — one compiled for 32-bit systems, one for 64-bit — share an identical structural hash, reuse the exact same code-signing certificate, and both carry a built-in routine to switch off Windows Defender. That alone would be a tidy defense-evasion case study.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence