FILEMembers
FILE

WZTeam KMS Trojan Stacks Five Evasion Layers Behind 23-Year Cert

Trojanized KMS activation tools circulating in piracy communities carry a self-signed WZTeam certificate valid until 2039, concealing a PowerShell downloader, Windows Defender disablement routines, and a probable Koadic post-exploitation stager. The campaign targets Mexico and the Philippines through bundled cracking toolkits, retrieving a secondary payload disguised as the Windows Desktop Window Manager process from a short-lived Dutch VPS.

Jun 23, 2026, 22:05 (UTC+9)Last seenJun 24, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC12RegionsMXPH

##A 23-Year Certificate and Five Stacked Evasion Layers: Inside the WZTeam KMS Trojan Chain Three UPX-packed Windows executables presenting as KMSAuto++ activation tools have been circulating with a self-issued code-signing certificate that carries a validity window stretching to the year 2039 — a deliberate, long-lived signing identity engineered to pass casual inspection at the moment a user decides whether to run a crack.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence