logo

Pirated Microsoft Office delivers malware cocktail on systems

ID: 7c9d04d6-e958-5250-a18c-7a84837c8a64

STIX ID: report--7c9d04d6-e958-5250-a18c-7a84837c8a64

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-05-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

AhnLab ASEC has identified an active campaign distributing a malicious cracked Microsoft Office installer via torrent sites that silently deploys a multi-component malware cocktail — including Orcus RAT, XMRig miner, 3Proxy proxy software, PureCrypter, and AntiAV—by running an obfuscated .NET loader that obtains download URLs from Telegram/Mastodon and fetches PowerShell-encoded payloads hosted on Google Drive/GitHub; the installer also installs a persistent 'Updater' task to reintroduce components after removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.