Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2024)

Dec 06, 2021Ravie Lakshmanan

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (1)

Users looking to activate Windows without using a digital license or a product key are being targeted by tainted installers to deploy malware designed to plunder credentials and other information in cryptocurrency wallets.

The malware, dubbed "CryptBot," is an information stealer capable of obtaining credentials for browsers, cryptocurrency wallets, browser cookies, credit cards, and capturing screenshots from the infected systems. Deployed via cracked software, the latest attack involves the malware masquerading as KMSPico.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2)

KMSPico is an unofficial tool that's used to illicitly activate the full features of pirated copies of software such as Microsoft Windows and Office suite without actually owning a license key.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (3)

"The user becomes infected by clicking one of the malicious links and downloading either KMSPico, Cryptbot, or another malware without KMSPico," Red Canary researcher Tony Lambert said in a report published last week. "The adversaries install KMSPico also, because that is what the victim expects to happen, while simultaneously deploying Cryptbot behind the scenes."

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (4)

The American cybersecurity firm said it also observed several IT departments using the illegitimate software instead of valid Microsoft licenses to activate systems, adding the altered KMSpico installers are distributed via a number of websites that claim to be offering the "official" version of the activator.

This is far from the first time cracked software has emerged as a conduit for deploying malware. In June 2021, Czech cybersecurity software company Avast disclosed a campaign dubbed "Crackonosh" that involved distributing illegal copies of popular software to break into and abuse the compromised machines to mine cryptocurrency, netting the attacker over $2 million in profits.


Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Malicious KMSPico Windows Activator Stealing Users' Cryptocurrency Wallets (2024)
Top Articles
Jefferson State Community College Libraries: A Writer's Handbook: Linking Sentences
10 Ways to Save on Renters Insurance
Murrieta Aeries Portal
4223 Macalester Street
Westcare Clinic Renton
911 Active Calls Caddo
Lohikeitto (Finnish Salmon Soup) Recipe on Food52
A Beginner's Guide to Silverlight
Mycoxemail Login
Valentina Arreaza
Play It Again Sports Knoxville Photos
Lynn Gruson
2022 Chevy Malibu Gas Button
Minute Clinic Mooresville Nc
Daily Press Escanaba Mi Obituaries
Jeffrey Buley Obituary
Jerry Eze Nsppd Live Today
What Do Porlocks Eat
Uw Madison Kb
Sumo Wrestling Wiki
Mr Biggs Soul Sonic Force Net Worth
German American Bank Owenton Ky
Guest Series | Dr. Matt Walker: Improve Sleep to Boost Mood & Emotional Regulation
Will Certifier Crossword Clue
Inbanithi Age
Lynda Mclaughlin Age
Milwaukee Nickname Crossword Clue
Strange World Showtimes Near Harkins Theatres Christown 14
Best Car Wash Soap for 2022
Academic Calendar | Touro University Worldwide
Cody Deal Lpsg
Putnam.schoology.com
Lowes Springhurst
Big Lots Furniture Leasing
World of Warships: Aslains Modpack - Alle Mods in einem Paket
Craigslist Bronx Ny Free Stuff
Smp Vs Cbpc
Meineke Lincolnton North Carolina
Encore Atlanta Cheer Competition
Nba Draftkings Picks For Tonight Cbs
A Place Next To Heaven: Fatin Ida Besik Ba Lalehan, come nuovo usato, spedizione gratuita... • EUR 12,37
Movierulz Plz 3
Depew Garbage Schedule 2023
Myrtle Lowater Obituary 2021 - Pederson-Volker Funeral Chapel & Cremation Services
Tighe Hamilton Hudson Ma Obituary
Fall River Ma Apartments For Rent Craigslist
Kumon Math Level H Answers
Busted Newspaper Kershaw County
Psjaisd Calendar
Mesh Tape Lowes
Miko Grimes Basketball Stats
Bank Account Verification - Datanamix
Latest Posts
Article information

Author: Kelle Weber

Last Updated:

Views: 6086

Rating: 4.2 / 5 (73 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Kelle Weber

Birthday: 2000-08-05

Address: 6796 Juan Square, Markfort, MN 58988

Phone: +8215934114615

Job: Hospitality Director

Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.