APTMembers
APT

Pirated Windows Activator Hides Five-Stage Intrusion Kit

A cracked KMSAuto/KMSSS activation tool bundles a self-signed 'WZTeam' certificate, a Chrome-disguised loader, a userland rootkit, a coinminer, and a decade-old vulnerable driver. Filed under an APT27 feed tag, the tradecraft on display looks far more like opportunistic crimeware than state-directed espionage.

Sep 4, 2026, 14:35 (UTC+9)Last seenSep 4, 2026Severity100ByCTX TeamActorAPT27TEMP.HippoIOC21MITRE58RegionsMY

A "free" copy of KMSAuto — the activation utility that generations of users have downloaded to skirt Windows licensing — carries a code-signing certificate that the distributor minted for itself, a loader dressed as a Google Chrome updater, a userland rootkit, a coin-mining payload, and a fifteen-year-old kernel driver still on the LOLDrivers vulnerable-driver list. None of those five components is individually novel.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence