Malicious KMSPico Windows Activator Steals Cryptocurrency Wallets from Users

KMSPico Windows Activator

KMSPico Windows Activator

Users looking to activate Windows without using a digital license or a product key are being targeted by tainted installers to deploy malware designed to plunder credentials and other information in cryptocurrency wallets.

The malware, dubbed “CryptBot,” is an information stealer capable of obtaining credentials for browsers, cryptocurrency wallets, browser cookies, credit cards, and capturing screenshots from the infected systems. Deployed via cracked software, the latest attack involves the malware masquerading as KMSPico.

Hacker Jailed for Stealing Millions of Dollars in Cryptocurrencies by SIM Hijacking

KMSPico is an unofficial tool that’s used to illicitly activate the full features of pirated copies of software such as Microsoft Windows and Office suite without actually owning a license key.

The user becomes infected by clicking one of the malicious links and downloading either KMSPico, Cryptbot, or another malware without KMSPico, …

 The adversaries install KMSPico also, because that is what the victim expects to happen, while simultaneously deploying Cryptbot behind the scenes.

Red Canary researcher Tony Lambert

The American cybersecurity firm said it also observed several IT departments using illegitimate software instead of valid Microsoft licenses to activate systems, adding the altered KMSpico installers are distributed via a number of websites that claim to be offering the “official” version of the activator.


KMSPico Windows Activator

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts