Cosmali Loader is an open-source malware loader/framework observed in a typosquatting campaign that impersonated the Microsoft Activation Scripts (MAS) project. In the reported activity, attackers used the malicious domain get.activate[.]win, mimicking the legitimate MAS domain get.activated.win, to trick users into copying and executing malicious PowerShell activation scripts. Execution of those scripts installed Cosmali Loader on victim systems.
Based on the provided reporting, Cosmali Loader was used to deploy additional payloads including the XWorm remote access trojan and cryptomining utilities. The associated infection chain involved PowerShell-based execution and persistence via registry modifications or scheduled tasks. Reported post-infection behaviors and artifacts in the broader campaign included persistent PowerShell processes, unauthorized network connections, and malware artifacts associated with Cosmali Loader and XWorm. The insecure control panel associated with the malware infrastructure reportedly allowed third parties to access infected systems, and pop-up warnings were observed on some victim machines.
The campaign was described as opportunistic and financially motivated rather than linked to a known APT group. It affected users seeking unofficial Windows or Microsoft Office activation, including both individuals and enterprise environments, and all Windows versions and major Microsoft Office versions were considered at risk if activation scripts were sourced from the malicious domain. Security researchers including RussianPanda and Karsten Hahn were cited in connection with identifying the campaign and its behavior. High-confidence indicators and infrastructure mentioned in the content include the typosquatted domain get.activate[.]win, malicious PowerShell activation scripts, delivery of XWorm RAT and cryptomining utilities, and the legitimate MAS domain get.activated.win used as the impersonation target.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader delivered via PowerShell scripts masquerading as a Windows activation tool (MAS), used to install additional malicious payloads.
Open-source malware framework used to establish persistence and deploy secondary payloads, including RATs and cryptominers.
Cosmali Loader is an open source loader malware that infects Windows systems, typically via malicious PowerShell scripts, and is used to deliver additional payloads such as cryptomining utilities and remote access trojans like XWorm.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.