FILEMembers
FILE

Free KMS Activator Ships With a Windows Defender Kill-Switch

A cracked-software binary sold as a free Windows activation tool stacks an untrusted code-signing certificate, UPX self-unpacking, a Defender-disable registry indicator, and anti-debug stalling into one package. It sits alongside a compiled loader re-dropped nearly 4.5 years apart under different filenames, pointing to durable crack-tool infrastructure rather than a bespoke intrusion kit.

Jul 12, 2026, 21:58 (UTC+9)Last seenJul 12, 2026Severity94ByCTX TeamActorGamaredon GroupCTIGIOC12MITRE19

A single cracked-software binary — sold to casual users as a free Windows activation tool — is quietly stacking four distinct evasion techniques into one package: a code-signing certificate that traces to a root nobody trusts, a UPX-packed payload that dumps itself at the original entry point, a named registry indicator for disabling Windows Defender, and anti-debug stalling behavior.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence