Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
ID: 8feb0eb1-ccdb-542e-8b22-9f3c6fe94fc4
STIX ID: report--8feb0eb1-ccdb-542e-8b22-9f3c6fe94fc4
Feed Name: Bleeping Computer
South Korean police say a Lithuanian national distributed a malicious KMSAuto Windows/Office activator containing clipper malware that scanned and replaced cryptocurrency wallet addresses from victims' clipboards; an estimated 2.8 million copies were distributed (Apr 2020–Jan 2023), resulting in roughly KRW 1.7 billion stolen across thousands of transactions, seizures during a 2024 raid, and the suspect's arrest and extradition in 2025. Authorities warn against using unofficial activators which can carry malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
