News: 0180456521

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Fake MAS Windows Activation Domain Used To Spread PowerShell Malware (bleepingcomputer.com)

(Thursday December 25, 2025 @04:00PM (msmash) from the psa dept.)


An anonymous reader shares a report:

> A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used [1]to distribute malicious PowerShell scripts that infect Windows systems with the 'Cosmali Loader'. BleepingComputer has found that multiple MAS users began reporting on Reddit yesterday that they received pop-up warnings on their systems about a Cosmali Loader infection.

>

> Based on the reports, attackers have set up a look-alike domain, "get[dot]activate[dot]win," which closely resembles the legitimate one listed in the official MAS activation instructions, "get[dot]activated[dot]win." Given that the difference between the two is a single character ("d"), the attackers bet on users mistyping the domain.



[1] https://www.bleepingcomputer.com/news/security/fake-mas-windows-activation-domain-used-to-spread-powershell-malware/



If you need to "activate" your operating system... (Score:2)

by ffkom ( 3519199 )

... you already are infected with malware, even before visiting such fake-site. Just get a better operating system for free.

Re: (Score:2)

by drinkypoo ( 153816 )

came here to say this but with slightly different snark

e.g. now do the official site

"And I'm right. I'm always right, but in this case I'm just a bit more
right than I usually am."

- Linus Torvalds