• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - This Windows key cracker is actually a remote Trojan

This Windows key cracker is actually a remote Trojan

Claire by Claire
March 23, 2022 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

Although modern people’s copyright awareness is much stronger than in the past, many people always want to see if there are cracked or free versions when installing operating systems or software based on speculation and petty gains. Recently, security research units have discovered a new malware campaign that disguises itself as a Windows operating system product key cracking tool, but is actually BitRAT or a remote access Trojan.

This Windows key cracker is actually a remote Trojan

Security research organization ASEC Recently, a special LUALAR RAT was discovered, spreading through the Korean online file sharing service Webhards. The file name directly named is a Windows key authenticator that can be quickly installed. As we all know, cracked and pirated software often contain malware that can invade hardware devices. However, many people often do not take these common sense issues seriously, or do not want to spend money to buy Windows keys. Therefore, malware creators will continue to produce and spread malware through such means.


▲Posted on the Windows Key Verifier on the Korean website

When unsuspecting users download a file named “Program.zip”, they only need to enter the password “1234” to unlock and decompress it. It contains a file named “W10DigitalActivation.exe”, which looks similar to a common cracker.

▲Files included in the compressed file

“W10DigitalActivation.exe” is a 7z SFX file that contains an actual verification tool named “W10DigitalActivation.msi” and malware named “W10DigitalActivation_Temp.msi”. When the user double-clicks on the exe file, it will install both msi files onto the computer. Since the malware and the verification tool are running at the same time, the user will mistakenly think that the tool is running normally.

▲Malware in 7z SFX files

There are other features packed into this key verification tool, and it is by no means as simple a program as it seems. As shown in the figure below, one of its functions is to use the powershell command to set the Windows startup program folder (the location where the downloaded program is installed) as the exclusion path of Windows Defender, and add the BitRAT process name “Software_Reporter_Tool.exe” to the exclusion items of Windows Defender.

The malware ultimately installed was a remote access Trojan named BitRAT. Since 2020, BitRAT has been sold through hacker forums and is continuously used by attackers. Because BitRAT is a Trojan used for remote access, attackers can take control of an infected system. BitRAT not only provides basic control functions such as running process tasks, service tasks, file tasks, and remote commands, but also provides additional options such as various information stealing functions, HVNC (hidden desktop), remote desktop, mining, and proxy servers.

▲BitRAT’s C&C control interface

Therefore, I hope that everyone will be more vigilant and cautious when facing all kinds of free, cracked and other pirated software on the Internet, and not be swayed by the mentality of being greedy for small gains, so as not to cause financial and personal damage to themselves due to small losses.

 

 

Source: KOCPC Chinese

Tags: Internet securitykeyPirated softwareremote controlTrojan horseWindows 10

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology