FILEMembers
FILE

KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector

A decade-old self-signed certificate authority is still binding a trojanised KMSpico activator chain that dropped two fresh LummaStealer payloads in May 2025. The installer bundle carries a WinDivert packet-capture driver and Formbook-derived anti-hook bypass code, making it far more capable than a typical piracy-lure campaign. An anomalous 4 KB component hits APT-grade YARA rules including a CISA-sourced Andariel bind-shell signature and two Cobalt Strike detections.

May 28, 2026, 02:47 (UTC+9)Last seenMay 28, 2026Severity44ByCTX TeamActorLazarus GroupHastati GroupIOC18MITRE42RegionsKE

Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence