VỮNG MÃI MỘT NIỀM TIN

The Dark Side of Pirated Software: A Global Malware Campaign Uncovered

  • 08/01/2026

A large-scale malware distribution campaign recently dismantled by South Korean authorities has exposed the serious risks associated with using pirated software. Notably, the malware was spread through KMSAuto – an illegal activation tool for Windows and Microsoft Office that is widely used around the world.

According to investigation results, approximately 2.8 million computers were infected, with many victims having their cryptocurrency stolen without any awareness.

A Global-Scale Malware Distribution Campaign

The suspect in this case is a 29-year-old Lithuanian national who was arrested and extradited from Georgia to South Korea with the coordination of Interpol. The individual is accused of embedding malicious code directly into the KMSAuto tool and distributing it widely on the internet to lure users into downloading and using it.

By exploiting users’ desire to activate software for free, the attacker turned a familiar tool into a large-scale malware delivery channel, silently compromising systems over an extended period of time.

Clipper Malware – Stealing Cryptocurrency Without Leaving Traces

The malware used in this campaign is known as clipper malware – a sophisticated attack method that specifically targets cryptocurrency users.

When victims copy a wallet address to make a transaction, the malware will:

  • Monitor clipboard data

  • Automatically replace the destination wallet address with one controlled by the attacker

  • Allow the transaction to proceed normally, while the funds are transferred entirely to the attacker

Because no abnormal behavior is visible during the transaction process, many victims only realize the loss after their assets have already disappeared.

(Image: Overview of the attack scheme – source: police.go.kr)

Severe Damage Over Multiple Years

According to investigators, from April 2020 to January 2023, the attacker:

  • Distributed 2.8 million malware-infected versions of KMSAuto

  • Conducted more than 8,400 fraudulent transactions

  • Stole approximately 1.7 billion KRW (around USD 1.2 million)

  • Impacted 3,100 cryptocurrency wallet addresses and multiple crypto exchanges

The scale and duration of the operation indicate a well-organized, long-running campaign that was extremely difficult to detect.

Pirated Software – An Open Door for Malware

Cybersecurity experts warn that illegal Windows activation tools such as KMSAuto have long been a common malware distribution channel, especially in countries with high rates of unlicensed software usage – including Vietnam.

Installing software from unverified sources can result in:

  • Loss of system control

  • Leakage of personal and financial data

  • Becoming a long-term victim of persistent cyberattacks

DTG Recommendations

To reduce cybersecurity risks, DTG strongly recommends that users and organizations:

  • Never use pirated software activation tools

  • Only install software from legitimate, licensed sources

  • Verify digital signatures and software publishers before installation

  • Deploy endpoint security solutions and keep systems regularly updated

  • Raise awareness about cybersecurity risks associated with “free” tools

This case serves as a clear warning: saving on software licensing costs may come at the expense of data, assets, and overall system security.

Source: BleepingComputer

 


Partner