Forgot your password?
typodupeerror
Security IT

Fake MAS Windows Activation Domain Used To Spread PowerShell Malware (bleepingcomputer.com) 35

An anonymous reader shares a report: A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the 'Cosmali Loader'. BleepingComputer has found that multiple MAS users began reporting on Reddit yesterday that they received pop-up warnings on their systems about a Cosmali Loader infection.

Based on the reports, attackers have set up a look-alike domain, "get[dot]activate[dot]win," which closely resembles the legitimate one listed in the official MAS activation instructions, "get[dot]activated[dot]win." Given that the difference between the two is a single character ("d"), the attackers bet on users mistyping the domain.

This discussion has been archived. No new comments can be posted.

Fake MAS Windows Activation Domain Used To Spread PowerShell Malware

Comments Filter:
  • ... you already are infected with malware, even before visiting such fake-site. Just get a better operating system for free.
  • by Tablizer ( 95088 ) on Thursday December 25, 2025 @08:03PM (#65882113) Journal

    "Wicrosoft Mindows" installed.

  • by david.emery ( 127135 ) on Thursday December 25, 2025 @08:04PM (#65882115)

    I thought vendor TLDs and the general proliferation of TLDs was supposed to make The Internet A Better Place (tm). Are you telling me that Microsoft uses .win but doesn't control it?

    • by ls671 ( 1122017 ) on Thursday December 25, 2025 @08:49PM (#65882151) Homepage

      Don't you find they control enough things already?

      Microsoft TLDs are: .azure .bing .hotmail .office .skype .windows .xbox

      Complaint about it not being hosted on a .windows domain.

      Control of the .win TLD
      Registry Management

      The .win top-level domain (TLD) is managed by Famous Four Media, which operates as the registry for this domain.
      Delegation and Oversight

      The .win TLD was delegated to the Root Zone on March 26, 2015, as part of ICANN's New gTLD Program. ICANN (the Internet Corporation for Assigned Names and Numbers) oversees the approval process for new TLDs and maintains the authoritative list of TLDs.
      Purpose and Governance

      The .win domain aims to create a dedicated space for online gaming resources, promoting consumer trust and choice within that sector. A Governance Council has been established to involve key stakeholders in the management and direction of the TLD.

      This structure ensures that the .win TLD is not only managed effectively but also aligns with the interests of its user community.

      • The more I look at this, the less I understand it. This is not a Microsoft -product-, but it's used to activate -Microsoft products-?

        • by ls671 ( 1122017 )

          I mentioned they could have used the .windows domain. Go figure.

        • Windows registration is notoriously buggy, and regular just refuses to work. This script does a bunch of stuff to force registration.

          I believe it works even if you don't have a key. Currently, the biggest use will be getting access to extended updates on Windows 10.

        • The more I look at this, the less I understand it. This is not a Microsoft -product-, but it's used to activate -Microsoft products-?

          It is a *SCAM*. You exemplify why people fall for it.

          • Well, it matches my expectations for Microsoft. Scams have to be believable to work.

            (No active Microsoft products here. I have one 12 year old Intel Mac that has a copy of Office for Mac on it, that I can boot up if there's something I can't read on the Mac. Plus I have a Windows 10 machine that I used for a bit of Arduino development. That too sits dead on a shelf.)

      • I agree that it's a bit much for Microsoft to control the *.win TLD. But that means they need to be very careful using it. Have a domain name ending in something that's clearly them and less likely to be confused, like *.microsoft.win, and have *that* completely under their control. (It would probably be simpler to just have a TLD of *.microsoft, which I wouldn't have any trouble with them controlling)

Old programmers never die, they just hit account block limit.

Working...