Windows KMS activator used by russian hackers to steal Ukrainians personal data

Windows 11 lifestyle

 

russian hacking group Sandworm attacks Ukrainian Windows users using Trojans in KMS activators and fake updates.

 

EclecticIQ researchers have discovered cyberattacks that began in late 2023, which are associated with the Sandworm (APT44) group. Hackers use the BACKORDER downloader to distribute the DarkCrystal RAT (DcRAT) malware, and also register attack domains via ProtonMail.

 

Sandworm deploys Trojans via fake Windows KMS activators. Once installed, they disable Windows Defender, record keystrokes, steal cookies, passwords, and system information, and then transfer them to attackers’ servers.

 

Hackers are taking advantage of the prevalence of pirated software in Ukraine, including government institutions, to massively infect devices. EclecticIQ warns that Sandworm attacks pose a serious threat to national security and critical infrastructure.

 

Twitter Russian propaganda

 

In the first half of 2024, russian hacker groups shifted the focus of their cyberattacks to targets related to military operations and service providers. This is stated in the analytical report “russian Cyber ​​Operations” for the first half of 2024, prepared by specialists of the State Service for Communications.

 

According to the report, if earlier Russian hackers focused on one-time attacks, now their strategy is aimed at entrenching in systems, covertly obtaining information and using cyber means to collect data on the results of their physical strikes.

 

The State Service for Communications notes that the IT sector demonstrates a high ability to quickly recover from cyberattacks and even strengthens after each incident. The report also analyzes new trends in Russian hacker tactics, identifies new threats, and provides lessons learned by Ukrainian cyber security experts from this experience.


Don't miss interesting news

Subscribe to our channels and read announcements of high-tech news, tes

Leave a Reply

Your email address will not be published. Required fields are marked *





Articles & testsArticles

Oppo A6 Pro smartphone review: ambitious Oppo A6 Pro (CPH2799)

Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.


Top news of 2025 on hi-tech.ua Top news 2025

Our editorial team traditionally sums up the results every year. We recently showcased the editors’ top devices. Now it’s time to share the top news stories from hi-tech.ua in 2025.


НовостиNews
| 12.45
Redmi Soundbar Speaker 2 Pro audio system – budget model from Xiaomi with a wireless subwoofer    
Redmi Soundbar Speaker 2 Pro

Xiaomi has expanded its audio system by releasing the Redmi Soundbar 2 Pro – an inexpensive soundbar with a wireless subwoofer and RGB lighting.

| 10.30
JBL introduces three new Quantum gaming headsets   
JBL Quantum 950X

JBL introduced an updated series of Quantum gaming headsets at CES 2026. It includes three models at once – Quantum 950X, Quantum 650X and Quantum 250