APTMembers
APT

KMSpico Crack Kit Adds Cryptominer, Clipper on Same Old Rail

A fresh sweep of Salty Spider's KMSpico/AutoKMS cluster found 19 new file hashes and four new URL variants, but zero new domains or IPs. The additions include a disguised XMRig miner and a three-sample clipper/clipbanker cohort sharing one imphash, confirming the decade-old crack-tool rail now monetizes via cryptojacking and clipboard hijacking.

Jul 15, 2026, 21:37 (UTC+9)Last seenJul 16, 2026Severity100ByCTX TeamActorSalty SpiderKuKuIOC73MITRE12

The latest sweep of Salty Spider's long-running KMSpico/AutoKMS distribution cluster turned up 19 new file hashes and four new URL variants — and not a single new IP address or domain. That lopsided delta is itself the story: the operators behind this pirated-Windows-activation funnel have left their hosting fabric completely untouched while quietly expanding what the funnel actually delivers.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence