
KMSpico Trojan Chain Delivers LummaStealer to Kenya's Tech Sector
A decade-old self-signed certificate authority is still binding a trojanised KMSpico activator chain that dropped two fresh LummaStealer payloads in May 2025. The installer bundle carries a WinDivert packet-capture driver and Formbook-derived anti-hook bypass code, making it far more capable than a typical piracy-lure campaign. An anomalous 4 KB component hits APT-grade YARA rules including a CISA-sourced Andariel bind-shell signature and two Cobalt Strike detections.
Four Windows executables carrying the same self-issued code-signing certificate have been circulating as KMSpico software activators for nearly a decade — and CTX Team's analysis of a recently surfaced indicator cluster shows that the same @ByELDI Certificate Authority, serial number CB C9 53 5C 7A 4B 70 DE 52 6C 01 39 FE AF 2C 9C, still binds the distribution chain today.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read