KMS Auto is an unauthorized key management and software activation utility commonly used to activate Microsoft products without a valid license. While the tool itself is not inherently malicious, cracked or repackaged versions of KMS Auto have been abused by threat actors for a long time as a delivery mechanism for malware.
Over the past several years, our analysis of critical incidents reveals that KMS Auto is frequently present on compromised endpoints, particularly in ransomware cases. While K7 telemetry clearly indicates its presence across the compromised systems, we could not definitively prove that KMS Auto served as the direct initial access vector in all the instances, though its presence strongly makes it a usual suspect for initial compromise. The following case study highlights one recent incident analysed in K7Labs where a routine KMSAuto activation served as the entry point for a multi-stage intrusion.
During our telemetry analysis, we observed an interesting multi-stage infection chain. An execution initially identified as KMSAuto eventually led to cryptocurrency mining activity, remote access software deployment, and finally the delivery of a Scareware payload masquerading as ransomware.
Traditional ransomware relies on cryptographic operations to encrypt files and then demands payment in exchange for a decryption mechanism. In contrast, a scareware-style payload could distort as a ransomware incident without performing the underlying encryption operation.
Kill Chain
Our telemetry revealed the following sequence of events:

The notable aspect of this activity was the time separation between stages. The infection did not immediately deploy all of its components. Instead, the threat actor maintained a presence on the system and introduced additional tooling over the course of several days.
Stage 1: KMS Auto as the Initial Vector
The activity began with the execution of KMS Auto on the affected system.
KMS Auto is frequently distributed through unofficial software repositories, torrent sites, cracked-software platforms, and other channels where modified versions can be bundled with additional payloads. Users downloading these packages may believe they are simply obtaining an activation utility, while the underlying package can contain additional malicious components. In this case, the KMS Auto execution represented the earliest observable event in the infection chain.
It is important to distinguish between the tool itself and its abuse. KMS Auto is not automatically an indicator of compromise. However, its execution from an unusual directory, particularly when downloaded from an untrusted source or accompanied by suspicious child processes, should raise the level of scrutiny.
Stage 2: XMRig Cryptocurrency Miner
Following the KMS Auto execution, our telemetry showed the deployment and execution of XMRig, an open-source cryptocurrency mining tool.
The presence of XMRig transformed what initially looked like an activation-tool execution into a clear indication of post-compromise activity.
Cryptocurrency miners are attractive to threat actors because they can generate financial returns while remaining relatively low-profile. Unlike ransomware, a miner does not necessarily need to disrupt the victim’s environment. It can operate in the background for extended periods, consuming CPU and other system resources.
In this case, the miner represented the second observable stage of the intrusion.
Stage 3: Remote Access
Several hours after the miner installation, telemetry showed the installation of ScreenConnect, a legitimate remote access and remote management solution.
Threat actors frequently abuse remote administration tools because they provide functionality already trusted in many enterprise environments. Rather than developing a custom remote-access implant, an attacker can deploy a legitimate remote management product and use it to maintain interactive access to a compromised host.
The software itself may be legitimate, but its deployment and usage within the context of an intrusion are malicious.
The following are the locations in which ScreenConnect was found:
- C:\ProgramData\HvHosts\ScreenConnect.WindowsClient.exe
- C:\ProgramData\OneDriveServer\OneDriveServer\OneDriveServer\ScreenConnect.WindowsClient.exe
The time gap between the miner activity and the ScreenConnect installation is particularly significant and suggests a more persistent operation in which additional capabilities were introduced after the initial compromise. A consistent 12-24 hour interval was observed between each incident instance in this case (may be susceptible to change to a different consistent time gap).
Following ScreenConnect activity, telemetry revealed the subsequent deployment of MeshAgent. Attackers frequently drop redundant RMM tools like MeshAgent to establish secondary backdoor persistence and ensure continuous remote control if the primary access channel is detected or revoked.
Stage 4: The Ransomware Hoax
Several hours later, the attacker dropped another payload onto the system. At first glance, the payload was thought to be ransomware.
But analysis showed that the payload did not actually encrypt the victim’s files. Instead, it relied primarily on ransomware-themed behavior intended to convince the victim that their data had been encrypted. This type of malware can be better characterized as scareware. The distinction is important. The objective is psychological rather than cryptographic.

Looking at the payload metadata, we can see that “APT36 Transparent Tribe Pakistanware” is mentioned predominantly, with a Pakistan flag as its icon, and the file is named “SecurityHealthServices.exe” to masquerade as a Windows Defender process. This payload is dropped in the “%ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup\*” location for All Users.

Once executed, the payload changes the desktop wallpaper to a Pakistani flag and launches a persistent overlay titled “pakistanware by APT36.” Locked on top of all other windows, this screen displays details designed to spook the victim into believing their files are locked. It uses classic ransomware tactics such as urgent warnings to spark immediate panic, while just functioning as scareware.


However, despite presenting itself as ransomware, our analysis did not identify any actual file-encryption activity or code. The malware targets executable files across the system, appending an additional ‘.exe’ extension to each filename and producing a double extension.
To maintain persistence, several Run, Run Once, and Startup Entries are created when executed.


It drops multiple self-copies into the “AppData” folder with a super hidden attribute to prevent them from appearing in standard File Explorer views.

Additional components, including batch scripts, VBS files, XML configurations, and executable binaries, were dropped into ‘C:\Users\Public\Recovery’ to support background execution.

RECOVERY_README.txt file contains the Ransom note to the victim, and the content of the executed PE was also embedded in it. Interestingly, the file did not contain any conventional ransomware payment instructions. It contained no cryptocurrency wallet address, ransom amount, payment deadline, or information on how the victim could contact the threat actor to obtain a decryption key.

Is the attribution of APT36 actually valid?
APT36 (also known as Transparent Tribe, Mythic Leopard, COPPER FIELDSTONE, or ProjectM) is a Pakistani state-aligned threat group specializing in cyber-espionage. Operating since roughly 2013, the collective focuses its intelligence collection efforts on advancing Pakistan’s strategic national interests.
Stealth is the essence of espionage. Adversaries do not treat MITRE ATT&CK as an operational manual. It is merely a defender’s model for observing behavior. Unlike cybercrime, targeted espionage ignores home users and focuses surgically on strategic, military, or diplomatic targets where the ultimate objective is intelligence.
While metadata links the payload to APT36, the logo is the Pakistan flag, and the overall indicators suggest their involvement, the evidence remains inconclusive. The payload behaved strictly as scareware rather than a true ransomware infection, and no targeted attacks against organizations or data theft were observed. Ultimately, the activity feels more like a hoax or a minor prank than a deliberate APT attack.
The key takeaway from this incident lies not in any single artifact, but in their collective correlation. While tools like KMSAuto, XMRig, ScreenConnect, and MeshAgent each have dual-use or legitimate applications, evaluating them in isolation yields a fragmented perspective. The true severity becomes clear when analyzing the sequence: dual-use utilities dropped in close temporal proximity, followed immediately by a ransomware-themed payload. Individually, these indicators might register as low-severity anomalies; combined, they provide conclusive evidence of a deliberate host compromise.
It shows just how effectively threat actors can mix legitimate admin tools, off-the-shelf software, and visual tricks to hold access and extract value from a compromised machine.
Based on our analysis and observation of continuous abuse of KMS Auto as an initial vector, we will classify KMS Auto under the HackTool category in our threat taxonomy going forward.
MITRE
Execution
T1204.002 User Execution: Malicious File
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Defense Evasion
T1036.005 Masquerading: Match Legitimate Name or Location
T1564.001 Hide Artifacts: Hidden Files and Directories
T1027.009 Obfuscated Files or Information: Embedded Payloads
Command and Control
T1105 Ingress Tool Transfer
T1219 Remote Access Software
Impact
T1496 Resource Hijacking
T1491.001 Defacement: Internal Defacement
IOC(s)
| Hash | Detection Name |
| 6DC495F33D4E1B6BEB27CD418C8ED5AE | Trojan ( 006dad991 ) |
| D24448EC0257ADFB258846B3317C3B7C | Trojan ( 006dad991 ) |
| D4E0F18025B3F8F329B136BBBEE6DEEA | Trojan ( 006dad991 ) |
| AC458ECE671FDDE066CE60E448F12BC0 | CryptoMiner ( 00516ff51 ) |
| D87D7173116EB5FA992AE2B4E57FA025 | RemoteTool ( 005cedd21 ) |
References:
- https://inferya.com/guides/pakistanware-ransomware-apt36/





