The Russian hacking group Sandworm has been exploiting pirated Microsoft Key Management Service (KMS) activation tools to target Ukrainian Windows systems for cyber-espionage. The operation has been using trojanized KMS activators and fake Windows updates to deploy malware, enabling large-scale data theft and espionage. This campaign has increased security risks for individuals, organizations, and critical infrastructure in Ukraine, with cybersecurity experts recommending the avoidance of pirated software and the adoption of robust security measures to counter these threats.
![](https://healsecurity.com/wp-content/uploads/2025/02/clickfix.webp.webp)
North Korean hackers spotted using ClickFix tactic to deliver malware
The North Korean group Kimsuky is employing a social engineering tactic called “ClickFix” to distribute malware to South Korean targets. The strategy tricks users into