logo

Russian military hackers deploy malicious Windows activators in Ukraine

ID: 671647c9-5f9a-555b-806b-774db76ce39e

STIX ID: report--671647c9-5f9a-555b-806b-774db76ce39e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-02-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Executive summary:** EclecticIQ attributes a series of late-2023 to January 2025 cyber-espionage campaigns against Windows users in Ukraine to Sandworm (APT44), which used trojanized Microsoft KMS activators and fake Windows updates to deploy a BACKORDER loader and DarkCrystal RAT, disable Windows Defender, and exfiltrate credentials, browser data, keystrokes, and screenshots via attacker-controlled servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.