A 29-year-old Lithuanian national was arrested and extradited to South Korea for allegedly distributing malware-laden versions of the KMSAuto Windows activation tool, which infected approximately 2.8 million systems worldwide between 2020 and 2023. The malware, classified as clipper malware, monitored victims’ clipboards for cryptocurrency addresses and replaced them with attacker-controlled wallets, resulting in the theft of digital assets through fraudulent redirection of crypto transactions. Authorities report that the campaign led to at least 8,400 unauthorized transfers from 3,100 wallets, with total losses estimated at around ₩1.7 billion (approximately $1.8 million), including several South Korean victims.
The suspect’s arrest followed a multi-year, international investigation coordinated by Interpol, culminating in his extradition from Georgia to South Korea. Law enforcement agencies highlighted that the malware was distributed primarily through pirated software channels, exploiting users seeking illegal Windows and Office activators. The operation demonstrates the significant risks associated with downloading and using pirated software, as well as the global reach and financial impact of cybercriminal campaigns targeting cryptocurrency transactions.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
By late December 2025, South Korean authorities and media reports disclosed the suspect's arrest and the scale of the malware operation. Officials also warned users about the risks of downloading software from untrusted sources and said they would continue international cooperation against cybercrime.
South Korean authorities announced that the 29-year-old Lithuanian national had been extradited from Georgia to South Korea. The extradition followed the multinational investigation into the KMSAuto-based clipper malware campaign and alleged cryptocurrency thefts.
South Korea's National Office of Investigation, working with international partners and Interpol, conducted a five-year cross-border investigation that traced illicit cryptocurrency flows and identified the Lithuanian national as the alleged operator. The investigation ultimately led to action in Georgia and South Korea.
Over the 2020–2023 campaign, authorities said the malware infected about 2.8 million Windows and Office systems globally. Investigators linked it to roughly 8,400 fraudulent transactions from 3,100 compromised wallets, with losses estimated at about ₩1.7 billion to ₩1.8 million in digital assets.
Between April 2020 and January 2023, a Lithuanian suspect allegedly spread malware disguised as the illegal Windows activator KMSAuto. The malware replaced copied cryptocurrency wallet addresses with attacker-controlled ones, enabling theft from victims in South Korea and other countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.