Malware (such as XMRig, OrcusRAT, etc.) disguised as MS Office crack is being distributed.

  • AhnLab Security Intelligence Center (ASEC) has revealed cases of attacks targeting Korean users by distributing RATs and coin miners disguised as cracks for Korean word processors [1].
  • The attackers continue to create and distribute various types of malware such as downloaders, coin miners, RATs, proxies, and anti-virus evasion tools.
  • They often disguise the malware as cracks for genuine Windows, Office authentication tools, or Korean word processors, leading to infections in many systems in Korea.
  • In addition, the attackers register task schedulers on infected systems to update the malware.

https://asec.ahnlab.com/ko/65307/