Windows KMS activator used by russian hackers to steal Ukrainians personal data
16.02.25
russian hacking group Sandworm attacks Ukrainian Windows users using Trojans in KMS activators and fake updates.
EclecticIQ researchers have discovered cyberattacks that began in late 2023, which are associated with the Sandworm (APT44) group. Hackers use the BACKORDER downloader to distribute the DarkCrystal RAT (DcRAT) malware, and also register attack domains via ProtonMail.
Sandworm deploys Trojans via fake Windows KMS activators. Once installed, they disable Windows Defender, record keystrokes, steal cookies, passwords, and system information, and then transfer them to attackers’ servers.
Hackers are taking advantage of the prevalence of pirated software in Ukraine, including government institutions, to massively infect devices. EclecticIQ warns that Sandworm attacks pose a serious threat to national security and critical infrastructure.

In the first half of 2024, russian hacker groups shifted the focus of their cyberattacks to targets related to military operations and service providers. This is stated in the analytical report “russian Cyber Operations” for the first half of 2024, prepared by specialists of the State Service for Communications.
According to the report, if earlier Russian hackers focused on one-time attacks, now their strategy is aimed at entrenching in systems, covertly obtaining information and using cyber means to collect data on the results of their physical strikes.
The State Service for Communications notes that the IT sector demonstrates a high ability to quickly recover from cyberattacks and even strengthens after each incident. The report also analyzes new trends in Russian hacker tactics, identifies new threats, and provides lessons learned by Ukrainian cyber security experts from this experience.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes

Samsung Galaxy Fold7: not a smartphone, not a tablet, something more
Samsung Galaxy Fold series of smartphones is notable for its folding design and large display. The new generation model had an even larger screen, advanced cameras, stronger hardware and improved ergonomics.
NVIDIA Blackwell – architecture with new capabilities for AI and content creation
NVIDIA technologies that were previously only available to owners of professional graphics cards are now open to ordinary users. Let’s talk about the capabilities of the Blackwell architecture in the field of artificial intelligence and content creation.

Garmin Instinct Crossover – hybrid smartwatch costs $600 with AMOLED screen, flashlight and sapphire glass smart watches
Garmin Instinct Crossover has a 1.2-inch AMOLED display with RevoDrive analog hands covered with Super-LumiNova luminescent compound.
New EcoFlow with 288 Wh capacity weigh less than 3 kilograms accumulator
EcoFlow has introduced a new line of portable charging stations in Europe, the Trail series. This device has already been on sale in the US


