Fake MAS Windows activation domain used to spread PowerShell malware
ID: ee7b5090-ffda-558e-962f-b4f589e17f96
STIX ID: report--ee7b5090-ffda-558e-962f-b4f589e17f96
Feed Name: Bleeping Computer
Threat Score
A typosquatted domain (get.activate.win) impersonating the MAS activation endpoint was used to serve malicious PowerShell that installs the Cosmali Loader, which researchers say delivered cryptomining utilities and the XWorm RAT; affected users reported popup warnings and project maintainers urged caution and verification of activation commands to avoid fetching payloads from look-alike domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
