logo

Fake MAS Windows activation domain used to spread PowerShell malware

ID: ee7b5090-ffda-558e-962f-b4f589e17f96

STIX ID: report--ee7b5090-ffda-558e-962f-b4f589e17f96

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-12-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A typosquatted domain (get.activate.win) impersonating the MAS activation endpoint was used to serve malicious PowerShell that installs the Cosmali Loader, which researchers say delivered cryptomining utilities and the XWorm RAT; affected users reported popup warnings and project maintainers urged caution and verification of activation commands to avoid fetching payloads from look-alike domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.