Russian military hackers deploy malicious Windows activators in Ukraine
ID: 671647c9-5f9a-555b-806b-774db76ce39e
STIX ID: report--671647c9-5f9a-555b-806b-774db76ce39e
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** EclecticIQ attributes a series of late-2023 to January 2025 cyber-espionage campaigns against Windows users in Ukraine to Sandworm (APT44), which used trojanized Microsoft KMS activators and fake Windows updates to deploy a BACKORDER loader and DarkCrystal RAT, disable Windows Defender, and exfiltrate credentials, browser data, keystrokes, and screenshots via attacker-controlled servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
