Unofficial Microsoft license activators are spreading BitRAT malware

Best 5.1 speakers for PC gaming
Best 5.1 speakers for PC gaming (Image credit: Microsoft)

What you need to know

  • A new malware campaign is underway, aiming to circulate BitRAT far and wide.
  • It relies on people using an unofficial Windows 10 Pro license activator.
  • As is often the case when attempting to pirate software, those who use the unofficial activator are going to end up with an infected machine.

A new malware campaign is up and running, ensuring that those who wanted a pirated copy of Windows 10 are at a particularly high risk of catching a nasty RAT (remote access trojan). Specifically, a BitRAT.

As spotted by AhnLab, the campaign's file-sharing platform of choice, as well as the text in the fake Windows activator's code, imply that the campaign is either being focused on — or originates from — Korea. Of course, once these dupe files hit the web, it doesn't really matter where they start since they all run the risk of spreading like wildfire. And this particular campaign is imitating Windows 10 Pro license activators. Windows is high on the list of digital goods pirates crave, so it's not hard to assume this particular BitRAT campaign poses a higher risk of infecting people than, say, a BitRAT package assuming the identity of less popular software.

You can check out AhnLab's afore-linked writeup for the technical details of how the malware works, but here's the long and short of it for average joes: Once a user makes their failed attempt at pirating Windows 10 Pro, they'll get BitRAT and with it, their system will be totally compromised. BitRAT has keylogging capabilities, will grant attackers access to your webcam and mic, can yoink your browser-logged credentials, and more. Cybercriminals love BitRAT malware because of how versatile it is and how much of a nightmare it can be for the piracy-inclined victim.

The point is, avoid pirating Windows 11, 10, 7, and any other versions, where at all possible. Microsoft even makes offers deliberately targeted at pirates so that everyone can save money and minimize cybersafety risks.

Robert Carnevale

Robert Carnevale is the News Editor for Windows Central. He's a big fan of Kinect (it lives on in his heart), Sonic the Hedgehog, and the legendary intersection of those two titans, Sonic Free Riders. He is the author of Cold War 2395. Have a useful tip? Send it to robert.carnevale@futurenet.com.

Read more
Microsoft CEO Satya Nadella in front of the Microsoft Copilot AI logo.
Windows 11 pirates have a new and unlikely ally — Microsoft Copilot
Binary code displayed on a laptop screen and Guy Fawkes mask are seen in this illustration photo.
Microsoft blocks critical Secure Boot loophole after over 7 months — fortifying Windows 11 against sophisticated firmware attacks camouflaged as verified UEFI apps
Windows 11 Taskbar closeup
Windows 11 hits a new market share milestone as Windows 10's death looms on the horizon
Satya Nadella on stage at an event in London talking about Copilot
Microsoft killed Skype, confirmed AI in Call of Duty, helped people pirate Windows 11, and began testing Office with ads — ALL IN A SINGLE WEEK
Windows Update
Unable to install security updates after freshly installing Windows 11? You're not alone
Windows 10 logo on a clock close to striking midnight.
Windows 10 'doomsday clock' pushes closer to midnight as Microsoft's unexpected rivals dominate an expanding PC category
Latest in Windows 10
Windows 10 Find My Device
How to enable Find My Device on Windows 10 to recover your PC if it's ever lost or stolen
Outlook Client Hero
Microsoft just made Windows 10 worse, and there's (almost) nothing you can do about it
Windows 10 Start menu on HP ZBook Studio G4
Microsoft will retroactively downgrade this part of Windows 10 next month
Former Microsoft Executive Vice President Terry Myerson stands in front of a presentation about Windows 10
Microsoft addresses the 'elephant in the room,' discusses upcoming end of Windows 10 support
Surface Hub 2S
Windows 10 for PCs is not the only version of Windows to reach end of support this year
Windows Insider program settings
Microsoft shuts down the Windows 10 Beta Channel just five months after reopening it
Latest in News
Cloud servers
Microsoft has killed "several" data center projects in the U.S. and Europe, according to reports — Microsoft responds (Updated)
Photo of Microsoft's new sign-in page for Xbox.com using the Microsoft Edge browser.
Over one billion users will get a new Microsoft user experience, and it has a dark mode
The Thing: Remastered key art
The Thing comes to Xbox Cloud Gaming's "Stream Your Own Game" library alongside other new arrivals
Promotional screenshot of heroes fighting a giant in Pillars of Eternity
Obsidian's classic Baldur's Gate successor 'Pillars of Eternity' is getting a surprise turn-based mode later this year, alongside other updates
Atomfall
Atomfall reviews and Metacritic scores are in: Here's a roundup of what everyone's saying about this new Game Pass survival game
Screenshot of one of the new flat world presets in Minecraft.
Minecraft testing new flat world presets and a better way to locate your friends in-game