APTMembers
APT

KMSpico Campaign Adds 9 Variants, Core Four-Layer Evasion Stack Unchanged

Nine new file indicators have expanded the Molerats-attributed KMSpico campaign to 17 known samples, yet not a single new network indicator has emerged. The operator is iterating outer installer shells while leaving intact a deeply engineered evasion architecture built around a self-issued 30-year certificate authority, Dotfuscator obfuscation, an embedded WinDivert driver, and Formbook-derived anti-hook bypass code.

Jun 14, 2026, 22:29 (UTC+9)Last seenJun 22, 2026Severity72ByCTX TeamActorMoleratsGaza CybergangIOC17MITRE19RegionsMY

Nine new file indicators have surfaced in the Molerats-attributed KMSpico campaign since CTX Team's earlier coverage, expanding the known file set to 17 samples — yet not a single new network indicator has emerged alongside them. The delta is entirely on the file side, and the pattern shows an operator iterating the outer delivery shell while leaving the campaign's most distinctive technical architecture completely intact: a four-layer evasion stack built around a self-issued certificate…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence