AhnLab Warns Against Malware Disguised as 'Illegal Windows Genuine Activation Tool' View original image


[Asia Economy Reporter Seungjin Lee] On the 17th, AhnLab discovered a case where malicious code was distributed by uploading a file disguised as an ‘illegal Windows genuine activation tool’ on a file-sharing site, and urged users to be cautious.


The attacker uploaded a compressed file (.zip) disguised as an illegal Windows genuine activation tool titled ‘[Latest][Super Simple] Windows Genuine Activation [One Click]’ on a specific domestic file-sharing site. The attacker detailed the usage instructions for the activation tool in the post to induce the installation of the malicious code.


When a user extracts the downloaded file and runs the executable inside (W10DigitalActivation.exe), a remote control malware called BitRAT is installed. After installation, it can perform malicious activities such as remote control of the infected PC, personal information theft, and cryptocurrency mining. Because the illegal activation tool also operates simultaneously with the malware installation, users find it difficult to detect the malware infection.


To prevent damage, users should ▲ use official websites when downloading files from the internet ▲ refrain from downloading illegal content ▲ avoid running files from unknown sources ▲ keep the OS, internet browsers, applications, and office software updated with the latest versions and security patches ▲ use the latest antivirus software and enable real-time monitoring, following security guidelines.


Currently, the V3 product line detects all discovered malicious files.



Jaejin Lee, a senior researcher at AhnLab’s analysis team, said, “Attacks targeting users who try to use software, games, and other content through illegal channels continue to occur. Attackers are expected to attempt similar attacks on various file-sharing sites in the future, so users must use content through official channels.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily(www.asiae.co.kr). All rights reserved.

Today’s Briefing