KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed

Summary
K7 Labs describes a multi-stage intrusion beginning with KMS Auto, followed by XMRig, ScreenConnect, MeshAgent and scareware that did not encrypt files. APT36/Transparent Tribe attribution remains inconclusive.
Key points
- K7 Labs observed KMS Auto execution as the earliest visible event in the intrusion, though the tool itself is not inherently malicious.
- XMRig was deployed after KMS Auto, followed by ScreenConnect and MeshAgent for remote access and backup control over several days.
- The final payload impersonated ransomware but did not encrypt files; it changed the wallpaper, displayed threatening messages and altered executable filenames.
- The payload used a deceptive Windows Defender-like filename, hidden copies, and Run and Startup entries to maintain persistence.
- Metadata and imagery suggested a possible APT36/Transparent Tribe connection, but the evidence was inconclusive and no targeted data theft was observed.
- The report identifies the sequence of dual-use tools and payloads as stronger evidence of compromise than any one artifact in isolation.
Article Details
- Attack Vectors
- Execution of KMS Auto was the earliest observed event in the intrusion; the source does not identify the download source for this instance.
- XMRig was deployed and executed after KMS Auto to mine cryptocurrency on the affected system.
- ScreenConnect and then MeshAgent were deployed to maintain remote access.
- A later scareware payload used a Windows Defender-like filename, startup persistence, hidden self-copies, and a ransomware-themed desktop overlay. The analysis found no file encryption.
- Defensive Notes
- Investigate KMS Auto execution from unusual directories, especially when associated with an untrusted download or suspicious child processes; KMS Auto alone is not necessarily an indicator of compromise.
- Correlate the sequence of activation-tool execution, mining, remote-management deployment, and the later scareware payload rather than evaluating each event in isolation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 6dc495f33d4e1b6beb27cd418c8ed5ae | Hash listed in the incident IOC table with a Trojan detection. |
| MD5 | ac458ece671fdde066ce60e448f12bc0 | Hash listed in the incident IOC table with a CryptoMiner detection. |
| MD5 | d24448ec0257adfb258846b3317c3b7c | Hash listed in the incident IOC table with a Trojan detection. |
| MD5 | d4e0f18025b3f8f329b136bbbee6deea | Hash listed in the incident IOC table with a Trojan detection. |
| MD5 | d87d7173116eb5fa992ae2b4e57fa025 | Hash listed in the incident IOC table with a RemoteTool detection. |
MITRE ATT&CK
T1027.009 · Embedded PayloadsThe executed PE content was embedded in the RECOVERY_README.txt ransom note.T1036.005 · Match Legitimate Resource Name or LocationThe payload used the filename SecurityHealthServices.exe to resemble a Windows Defender process.T1204.002 · Malicious FileThe intrusion began with the user's execution of KMS Auto on the affected system.T1219 · Remote Access ToolsScreenConnect and MeshAgent were deployed to maintain remote control of the compromised system.T1491.001 · Internal DefacementThe payload changed the desktop wallpaper to a Pakistani flag and displayed a persistent, threatening overlay.T1496 · Resource HijackingXMRig was deployed and executed to mine cryptocurrency using the affected system.T1547.001 · Registry Run Keys / Startup FolderThe scareware payload created Run, Run Once, and Startup entries for persistence.T1564.001 · Hidden Files and DirectoriesThe payload placed self-copies in AppData with super hidden attributes.
Threat Actors
APT36The source identifies Transparent Tribe, Mythic Leopard, COPPER FIELDSTONE, and ProjectM as aliases. Payload metadata suggested possible involvement in this incident, but attribution was inconclusive.COPPER FIELDSTONEIdentified as an alias of APT36; the incident's possible attribution to the group was inconclusive.Mythic LeopardIdentified as an alias of APT36; the incident's possible attribution to the group was inconclusive.ProjectMIdentified as an alias of APT36; the incident's possible attribution to the group was inconclusive.Transparent TribeIdentified as an alias of APT36; the incident's possible attribution to the group was inconclusive.
Products
MeshAgentKMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware.ScreenConnectKMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware.
Tools
KMS AutoKMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware.XMRigKMS Auto was abused as an initial entry point in a multi-stage intrusion that led to XMRig mining, ScreenConnect and MeshAgent remote access, and a scareware payload masquerading as ransomware.