Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2024)

Dec 06, 2021Ravie Lakshmanan

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (1)

Users looking to activate Windows without using a digital license or a product key are being targeted by tainted installers to deploy malware designed to plunder credentials and other information in cryptocurrency wallets.

The malware, dubbed "CryptBot," is an information stealer capable of obtaining credentials for browsers, cryptocurrency wallets, browser cookies, credit cards, and capturing screenshots from the infected systems. Deployed via cracked software, the latest attack involves the malware masquerading as KMSPico.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2)

KMSPico is an unofficial tool that's used to illicitly activate the full features of pirated copies of software such as Microsoft Windows and Office suite without actually owning a license key.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (3)

"The user becomes infected by clicking one of the malicious links and downloading either KMSPico, Cryptbot, or another malware without KMSPico," Red Canary researcher Tony Lambert said in a report published last week. "The adversaries install KMSPico also, because that is what the victim expects to happen, while simultaneously deploying Cryptbot behind the scenes."

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (4)

The American cybersecurity firm said it also observed several IT departments using the illegitimate software instead of valid Microsoft licenses to activate systems, adding the altered KMSpico installers are distributed via a number of websites that claim to be offering the "official" version of the activator.

This is far from the first time cracked software has emerged as a conduit for deploying malware. In June 2021, Czech cybersecurity software company Avast disclosed a campaign dubbed "Crackonosh" that involved distributing illegal copies of popular software to break into and abuse the compromised machines to mine cryptocurrency, netting the attacker over $2 million in profits.


Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2024)
Top Articles
United States - Credit Rating
S&P 500 Dividend Yield Monthly Trends: S&P 500 Earnings
WALB Locker Room Report Week 5 2024
It's Official: Sabrina Carpenter's Bangs Are Taking Over TikTok
Mama's Kitchen Waynesboro Tennessee
Robinhood Turbotax Discount 2023
Botanist Workbench Rs3
Eric Rohan Justin Obituary
Naturalization Ceremonies Can I Pick Up Citizenship Certificate Before Ceremony
Farmers Branch Isd Calendar
Lichtsignale | Spur H0 | Sortiment | Viessmann Modelltechnik GmbH
What Was D-Day Weegy
Baseball-Reference Com
Wunderground Huntington Beach
Slushy Beer Strain
C Spire Express Pay
1-833-955-4522
Ups Access Point Lockers
Jayah And Kimora Phone Number
We Discovered the Best Snow Cone Makers for Carnival-Worthy Desserts
Viha Email Login
Ppm Claims Amynta
Busted News Bowie County
Parc Soleil Drowning
Panolian Batesville Ms Obituaries 2022
[PDF] NAVY RESERVE PERSONNEL MANUAL - Free Download PDF
All Obituaries | Gateway-Forest Lawn Funeral Home | Lake City FL funeral home and cremation Lake City FL funeral home and cremation
Stihl Dealer Albuquerque
Silky Jet Water Flosser
Vivaciousveteran
Move Relearner Infinite Fusion
Violent Night Showtimes Near Johnstown Movieplex
Firefly Festival Logan Iowa
Sams Gas Price Sanford Fl
Shiny Flower Belinda
LG UN90 65" 4K Smart UHD TV - 65UN9000AUJ | LG CA
Lininii
Pokemmo Level Caps
M3Gan Showtimes Near Cinemark North Hills And Xd
Helloid Worthington Login
Leatherwall Ll Classifieds
20+ Best Things To Do In Oceanside California
Complete List of Orange County Cities + Map (2024) — Orange County Insiders | Tips for locals & visitors
Improving curriculum alignment and achieving learning goals by making the curriculum visible | Semantic Scholar
Ross Dress For Less Hiring Near Me
The Realreal Temporary Closure
Citroen | Skąd pobrać program do lexia diagbox?
Mynord
DL381 Delta Air Lines Estado de vuelo Hoy y Historial 2024 | Trip.com
Used Auto Parts in Houston 77013 | LKQ Pick Your Part
View From My Seat Madison Square Garden
login.microsoftonline.com Reviews | scam or legit check
Latest Posts
Article information

Author: Kelle Weber

Last Updated:

Views: 6086

Rating: 4.2 / 5 (73 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Kelle Weber

Birthday: 2000-08-05

Address: 6796 Juan Square, Markfort, MN 58988

Phone: +8215934114615

Job: Hospitality Director

Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.