Lithuanian suspect arrested over KMSAuto malware that infected 2.8M systems
ID: 3cab3422-a6ab-5f72-aea8-2188d9201ba0
STIX ID: report--3cab3422-a6ab-5f72-aea8-2188d9201ba0
Feed Name: Security Affairs
Threat Score
A Lithuanian national was arrested after allegedly distributing a trojanized KMSAuto activation tool containing clipboard‑stealing 'clipper' malware that monitored and replaced cryptocurrency addresses; the malicious installer was downloaded around 2.8 million times (2020–2023), was linked to ~8,400 fraudulent transfers from 3,100 wallets totaling approximately ₩1.7 billion, and investigators executed seizures and an extradition as part of an international probe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
