KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed

· Original article ↗

Summary

K7 Labs describes a multi-stage intrusion beginning with KMS Auto, followed by XMRig, ScreenConnect, MeshAgent and scareware that did not encrypt files. APT36/Transparent Tribe attribution remains inconclusive.

Key points

  • K7 Labs observed KMS Auto execution as the earliest visible event in the intrusion, though the tool itself is not inherently malicious.
  • XMRig was deployed after KMS Auto, followed by ScreenConnect and MeshAgent for remote access and backup control over several days.
  • The final payload impersonated ransomware but did not encrypt files; it changed the wallpaper, displayed threatening messages and altered executable filenames.
  • The payload used a deceptive Windows Defender-like filename, hidden copies, and Run and Startup entries to maintain persistence.
  • Metadata and imagery suggested a possible APT36/Transparent Tribe connection, but the evidence was inconclusive and no targeted data theft was observed.
  • The report identifies the sequence of dual-use tools and payloads as stronger evidence of compromise than any one artifact in isolation.

Article Details

Attack Vectors
  • Execution of KMS Auto was the earliest observed event in the intrusion; the source does not identify the download source for this instance.
  • XMRig was deployed and executed after KMS Auto to mine cryptocurrency on the affected system.
  • ScreenConnect and then MeshAgent were deployed to maintain remote access.
  • A later scareware payload used a Windows Defender-like filename, startup persistence, hidden self-copies, and a ransomware-themed desktop overlay. The analysis found no file encryption.
Defensive Notes
  • Investigate KMS Auto execution from unusual directories, especially when associated with an untrusted download or suspicious child processes; KMS Auto alone is not necessarily an indicator of compromise.
  • Correlate the sequence of activation-tool execution, mining, remote-management deployment, and the later scareware payload rather than evaluating each event in isolation.

Indicators of compromise

TypeIndicatorContext
MD56dc495f33d4e1b6beb27cd418c8ed5aeHash listed in the incident IOC table with a Trojan detection.
MD5ac458ece671fdde066ce60e448f12bc0Hash listed in the incident IOC table with a CryptoMiner detection.
MD5d24448ec0257adfb258846b3317c3b7cHash listed in the incident IOC table with a Trojan detection.
MD5d4e0f18025b3f8f329b136bbbee6deeaHash listed in the incident IOC table with a Trojan detection.
MD5d87d7173116eb5fa992ae2b4e57fa025Hash listed in the incident IOC table with a RemoteTool detection.

MITRE ATT&CK

Threat Actors

Products

Tools

Countries

Related Articles