Typosquatted Domains Spread Cosmali Loader via PowerShell Malware

Typosquatted Domains Spread Cosmali Loader via PowerShell Malware

First seen 26 Dec 2025, 10:14 UTC BleepingcomputerGigazine 92% similarity 36.9

Article Content

Browse articles
ThreatCluster

Users of the Microsoft Activation Scripts (MAS) tool have reported receiving pop-up warnings about a Cosmali Loader infection after mistakenly entering a typosquatted domain. The malicious domain 'get.activate[.]win' was used to distribute PowerShell scripts that infect Windows systems. This incident highlights the risks associated with typosquatting in software activation processes.

ThreatCluster AI

Community

Browse all →