
APTMembers
APTKMS Crack Tool's Twin Binaries Hide Defender-Killer, Konni YARA Hits
Two architecture variants of a pirated Windows activation tool share an identical vhash and the same untrusted-root code-signing certificate, while both embed a Defender-disabling registry routine. A Konni malware YARA hit and a WinDivert driver flag sit atop an otherwise clean sandbox verdict.
Jul 28, 2026, 21:35 (UTC+9)Last seenJul 28, 2026Severity62ByCTX TeamActorGamaredon GroupCTIGIOC7MITRE36RegionsARBRCICODE
Two Windows binaries branded as a routine Microsoft-activation "crack" — one compiled for 32-bit systems, one for 64-bit — share an identical structural hash, reuse the exact same code-signing certificate, and both carry a built-in routine to switch off Windows Defender. That alone would be a tidy defense-evasion case study.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence