Gigazine
Typosquatted Domains Spread Cosmali Loader via PowerShell Malware
First seen 26 Dec 2025, 10:14 UTC
•
•92% similarity
•36.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Users of the Microsoft Activation Scripts (MAS) tool have reported receiving pop-up warnings about a Cosmali Loader infection after mistakenly entering a typosquatted domain. The malicious domain 'get.activate[.]win' was used to distribute PowerShell scripts that infect Windows systems. This incident highlights the risks associated with typosquatting in software activation processes.
ThreatCluster AI