Cosmali Loader is a Windows-based malware loader that delivers PowerShell-based payloads.
Cosmali Loader is a Windows-based malware loader that delivers PowerShell-based payloads. Recent reports describe campaigns using fake Windows activation domains to host or spread its components, indicating its role in PowerShell-driven infection chains and lure-based delivery.
Users of the Microsoft Activation Scripts (MAS) tool have reported receiving pop-up warnings about a Cosmali Loader infection after mistakenly entering a typosquatted domain. The malicious domain 'get.activate[.]win'…