Attackers set up a typosquatted domain, get.activate[.]win, closely resembling the legitimate Microsoft Activation Scripts (MAS) domain, to distribute malicious PowerShell scripts. Users who mistyped the official MAS activation URL were infected with the Cosmali Loader malware, which deployed additional payloads such as cryptomining utilities and the XWorm remote access trojan (RAT). The campaign exploited the popularity of the open-source MAS tool, which is used to automate Windows and Office activation, by relying on a single-character typo to trick users into visiting the malicious site.
Security researchers discovered that the Cosmali Loader's control panel was insecure, allowing third parties to access compromised systems. Some researchers used this access to notify victims of their infection via pop-up warnings. The incident highlights the risks associated with using unofficial activation tools and the dangers of typosquatting, as well as the potential for malware to be distributed through seemingly minor user errors during software activation processes.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Following disclosure of the typosquatting attack, MAS project maintainers and security experts advised users not to run remote code from unofficial sources and to carefully verify commands to avoid similar infections. The case was highlighted as another example of malware being distributed through unofficial Windows activation tools.
Security researchers including RussianPanda and Karsten Hahn analyzed the campaign and found the malware's control panel was insecure. This allowed a researcher to send pop-up warnings to infected victims, revealing the scope and mechanics of the operation.
Attackers registered and used the typosquatted domain get.activate[.]win to impersonate the legitimate Microsoft Activation Scripts (MAS) site. Users who mistyped the MAS command executed malicious PowerShell that installed Cosmali Loader, which then deployed cryptomining tools and the XWorm RAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.