HomeSecurityMalicious KMSpico installers are used to steal crypto wallets

Malicious KMSpico installers are used to steal crypto wallets

Cybercriminals are distributing modified KMSpico installers to infect Windows with malware that steals crypto wallets.

KMSpico installers
Malicious KMSpico installers are used to steal crypto wallets

The malicious activity was detected by Red Canary, who warn that pirated software can put users at great risk.

See also: Discord malware campaign targets crypto and NFT communities

KMSPico is a popular Microsoft Windows and Office product activator that simulates a Windows Key Management Services (KMS) server to activate licenses illegally.

According to Red Canary, many IT departments are using KMSPico instead of legitimate Microsoft software licenses.

Infected product activators

KMSPico is commonly distributed through pirated software and crack sites that bundle the tool in installers that contain adware and malware.

According to the researchers, many sites have been created for the distribution of KMSPico, and all claim to be the official website.

A malicious KMSPico installer analyzed by Red Canary comes in a self-extracting executable, like 7-Zip, and contains a real KMS server emulator and Cryptbot.

“ The user gets infected by clicking on one of the malicious links and downloads KMSPico and Cryptbot or other malware without KMSPico ,” the experts explain

See also: Bitmart hacked: Hackers stole $196 million from the platform

“Attackers install KMSPico because this victim is waiting, while at the same time they silently deploy Cryptbot“.

crypto wallets Cryptbot

The malicious software is hidden by the CypherIT packer that prevents its detection by security software. Then, this installer uses a script that is capable of detecting sandboxes and AV emulation, so that it does not run on researchers' devices.

See also: Hackers exploit a new Zoho ServiceDesk exploit

Additionally, Cryptbot checks for the presence of “%APPDATA%\Ramson” and executes the self-delete routine if the folder exists.

In summary, Cryptbot is able to collect sensitive data from the following applications:

  • Atomic cryptocurrency wallet
  • Avast Secure web browser
  • Brave browser
  • Ledger Live cryptocurrency wallet
  • Opera Web Browser
  • Waves Client and Exchange cryptocurrency applications
  • Coinomi cryptocurrency wallet
  • Google Chrome web browser
  • Jaxx Liberty cryptocurrency wallet
  • Electron Cash cryptocurrency wallet
  • Electrum cryptocurrency wallet
  • Exodus cryptocurrency wallet
  • Monero cryptocurrency wallet
  • MultiBitHD cryptocurrency wallet
  • Mozilla Firefox web browser
  • CCleaner web browser
  • Vivaldi web browser

The above shows that choosing a pirated software, such as KSMPico, to save money is not a good idea, since there are many risks, as in this case with crypto wallets.

The loss of revenue due to ransomware and cryptocurrency theft that can be caused by installing pirated software will certainly be greater than the cost of Windows and Office licenses.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS