The Dark Side of Fame: Pakistani Actors and Malware Distribution

A sophisticated cybercriminal network based in Pakistan has launched more than 300 cracking websites since 2021, targeting users seeking pirated software with information-stealing malware. This operation is one of the largest documented cases of coordinated malware distribution through seemingly legitimate software portals, impacting both corporate and individual users worldwide.


The network exploits the allure of free software, tricking victims into downloading malicious executables disguised as activation tools. Once executed, these payloads steal browser credentials, cryptocurrency wallets, and sensitive data, sending the information to command-and-control servers.
The campaign employs advanced techniques, including search engine optimization and Google Ads, to attract victims searching for cracked software.


Analysts from Intrinsec traced the operation back to domains like kmspico.io, revealing a network of Pakistani freelancers who may have been unaware of the malicious intent behind their projects.
The operation relies on a centralized DNS infrastructure, primarily using ns1.filescrack.com, and is hosted by a Pakistani provider, 24xservice. Domain registration records link to real identities, indicating security lapses that allowed for attribution. The malware distribution is monetized through InstallPP, a pay-per-install service, highlighting the professional nature of this cybercrime network.
- Other (43)
- Ransomware (154)
- Events and News (27)
- Features (45)
- Security (485)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (36)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (231)
- Cyber Attack (299)
- Data Backup (13)
- Data Breach (127)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (77)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (74)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (25)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (40)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (29)