CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Typosquatted MAS Domain Distributes Cosmali Loader Malware

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool has been used to distribute the Cosmali Loader malware via malicious PowerShell scripts. Users mistyping 'get.activated.win' as 'get.activate[.]win' were infected, leading to warnings about the malware on their systems. The malware panel is insecure, exposing infected systems to unauthorized access. The Cosmali Loader delivers cryptomining utilities and the XWorm remote access trojan (RAT). The campaign highlights the risks of typosquatting and the importance of verifying commands before execution.

Timeline

  1. 24.12.2025 19:44 1 articles · 23h ago

    Typosquatted MAS Domain Distributes Cosmali Loader Malware

    A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool has been used to distribute the Cosmali Loader malware via malicious PowerShell scripts. Users mistyping 'get.activated.win' as 'get.activate[.]win' were infected, leading to warnings about the malware on their systems. The malware panel is insecure, exposing infected systems to unauthorized access. The Cosmali Loader delivers cryptomining utilities and the XWorm remote access trojan (RAT). The campaign highlights the risks of typosquatting and the importance of verifying commands before execution.

    Show sources

Information Snippets