Windows systems have been infected with the new Cosmali Loader through illicit PowerShell scripts deployed through a typosquatted Microsoft Activation Scripts tool domain, BleepingComputer reports.
Threat actors were reported to have used the "get.activate[.]win" domain that impersonates the official "get.activated.win" domain containing legitimate MAS activation instructions to spread the Cosmali Loader, which enabled the injection of the XWorm remote access trojan alongside cryptomining tools, according to security researcher RussianPanda, who noted the potential link between the pop-up notifications of compromise reported by multiple MAS users and similar notices identified by GDATA malware researcher Karsten Hahn. Additional details regarding the origins of the notifications remain uncertain.
However, users have already been advised to be wary of typed commands prior to their execution. "Please take extra care to verify the commands you type before running them, or download the MAS AIO script from our GitHub," said MAS maintainers in a post on X, formerly Twitter.
Threat actors were reported to have used the "get.activate[.]win" domain that impersonates the official "get.activated.win" domain containing legitimate MAS activation instructions to spread the Cosmali Loader, which enabled the injection of the XWorm remote access trojan alongside cryptomining tools, according to security researcher RussianPanda, who noted the potential link between the pop-up notifications of compromise reported by multiple MAS users and similar notices identified by GDATA malware researcher Karsten Hahn. Additional details regarding the origins of the notifications remain uncertain.
However, users have already been advised to be wary of typed commands prior to their execution. "Please take extra care to verify the commands you type before running them, or download the MAS AIO script from our GitHub," said MAS maintainers in a post on X, formerly Twitter.
