
C&CMembers
C&CSalty Spider's KMSpico Crack-Tool Cluster Stays Frozen—And Still Works
A years-old @ByELDI self-signed certificate chain still wraps the same KMSpico/AutoKMS activator binaries, paired with a separately-respun clipboard-hijacking miner family. This snapshot adds no new infrastructure at all, pruning 19 file rows and 4 URLs instead.
Jul 15, 2026, 21:46 (UTC+9)Last seenJul 16, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC50MITRE11
Four KMS-activation installers circulating under the KMSpico and AutoKMS banners all carry the identical code-signing chain from an entity calling itself "@ByELDI" — a self-issued authority whose root nothing trusts, wrapped around binaries that also co-fire generic RAT-detection and anti-hook YARA rules that have nothing to do with license activation.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence