Monday, June 19th 2023

Reports Warn of Pirated Windows 10 ISOs Containing Dangerous Malware

According to a report published by Bleeping Computer last week and research conducted by the Doctor Web team, nefarious online organizations are distributing Windows 10 ISO files laced with extremely dangerous clipper malware variants. Microsoft ceased direct sales of licenses for its last gen operating system earlier this year, and a select bunch of folks are resorting to grabbing copies (for free) from pirate sources. The Doctor Web alert states: "(we) discovered a malicious clipper program in a number of unofficial Windows 10 builds that cybercriminals have been distributing via a torrent tracker. Dubbed Trojan.Clipper.231, this trojan app substitutes crypto wallet addresses in the clipboard with addresses provided by attackers. As of this moment, malicious actors have managed to steal cryptocurrency in an amount equivalent to about $19,000 (USD)."

It continues: "At the end of May 2023, a customer contacted Doctor Web with their suspicion that their Windows 10 computer was infected. The analysis our specialists carried out confirmed the presence of trojan applications in the system. These were Trojan.Clipper.231 stealer malware as well as the Trojan.MulDrop22.7578 dropper and Trojan.Inject4.57873 injector, which were used to launch the clipper. Doctor Web's virus laboratory successfully localized all these threats and neutralized them." It seems that hackers are hiding cryptocurrency hijackers within Extensible Firmware Interface (EFI) partitions, thus evading detection by antivirus software(s).

New Windows 10 licenses are still available to purchase from third-party retailers, and Microsoft does officially distribute W10 ISOs for existing customers—so it is odd that some system builders are relying on nefarious sources to "acquire" operating systems. TPU recommends using the official Windows 10 installation media tool, or a direct download of an ISO via non-Windows browser user agents—Bleeping Computer has detailed the methodology of mimicking a smartphone or tablet browser session here.

Doctor Web shared and warned that the following Windows builds as infected sources, but they anticipate that even more examples exist on torrents and other illegal distribution sites:
  • Windows 10 Pro 22H2 19045.2728 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2913 + Office 2021 x64 by BoJlIIIebnik [RU, EN].iso
  • Windows 10 Pro 22H2 19045.2913 x64 by BoJlIIIebnik [RU, EN].iso
Sources: Bleeping Computer, PC World, Dr Web
Add your own comment

39 Comments on Reports Warn of Pirated Windows 10 ISOs Containing Dangerous Malware

#26
chrcoluk
FreedomEclipseMan... I gave up with pirated copies of windows when i found out i could buy legit grey market windows keys for very very little money and the best part of grey market keys is microsoft doesnt even care if you bought it for the price of a chicken dinner and one or two beers. People who buy the keys for their own system builds arent their bread and butter. They are still making money off you regardless by selling your data :laugh:

My old technet keys still work, valid for windows 8 and 10, and I assume 11 as well, like you said its practically free now.
Posted on Reply
#27
Dr. Dro
mb194dcCheaper than $0 ?

We've always got Linux as well for $0, value.

Frankly Windows has been getting worse for about 15 years and the sooner we get mass adoption of an alternative , like Android for desktop or similar friendly Linux based OS, the better the world of computing will be. In fact, I'd say Microsoft hasn't produced a decent product generally for a similar time frame.

All they've done is made worse versions of existing software and gone SAAS, cloud, Azure, 365 ,Windows 10/11, and charge for them monthly, more $ for worse products.
I agree, workflow-wise. I wish Microsoft had a power user version of Windows that had the same shell as NT4 or 2000.

Light as a feather, quick as lightning no fluff... What a dream that would be.
Posted on Reply
#28
R-T-B
kapone32If it was, you would not be able to update Windows after a while and would not be able to get official MS support.
That's really not evidence of legality at all. Just sayin'

I mean it is pretty much a EULA violation, but I ain't got time for this shitty discussion again...
Posted on Reply
#30
Prima.Vera
ALWAYS the Russian or Chinese torrents are the ones with such issues.... Mostly the Russian ones...
Posted on Reply
#31
kondamin
FreedomEclipseMan... I gave up with pirated copies of windows when i found out i could buy legit grey market windows keys for very very little money and the best part of grey market keys is microsoft doesnt even care if you bought it for the price of a chicken dinner and one or two beers. People who buy the keys for their own system builds arent their bread and butter. They are still making money off you regardless by selling your data :laugh:

I’m kinda expecting a heavy crackdown on those.
They became so visible
Posted on Reply
#32
Tomorrow
KissamiesJust wondering that who uses those when you can get a legit .iso from MS itself?
Exactly. This is not 2000's any more. Safe alternatives exist. I use uupdump.net myself to get various Windows ISO's. They are downloaded piece by piece from MS servers and the downloader itself is a script that can be altered or examined by the end user. Also the ISO's themselves can be customized to a degree.
Posted on Reply
#33
lexluthermiester
mb194dcWe've always got Linux as well for $0, value.
Many people keep saying this and it's usually total BS. Not really an option for some people.
dicobaltI can't imagine why anyone would download a Windows image from a non-Microsoft website.
That's your limitation.
kondaminI’m kinda expecting a heavy crackdown on those.
They became so visible
You would be wrong. There are specific reasons why that will not happen.
Posted on Reply
#34
NC37
Why pirate it when you can get the keys for under $1 on key sites? Just silly.
Posted on Reply
#35
Bomby569
Download from trusted sources only, private trackers, scene releases, they are and always have been as safe as from any MS website.
If you download from random places on the internet shit happens, it's the same with games or any other pirated app, nothing new. Stupid news for stupid people.

f MS, i'm certainly not supporting them
Posted on Reply
#37
thegnome
The best option is probably using legit ISO's with some cracking stuff afterwards, pretty sure that stuff is a lot more common too
Posted on Reply
#38
GoFigureItOut
This makes me even more skeptical about Ghost Spectre. I wonder if its possible for a virus to be embedded that certain AV cannot detect them
Posted on Reply
#39
lexluthermiester
Bomby569Stupid news for stupid people.
I like that. There's some truth to it as well.
UdyrUnderstandable, but if you say "John and other students", it implies John is a student as well.

In this case, the correct use would be "torrents and illegal distribution sites".
@T0@st This. Proper wording is a thing.
Posted on Reply
Add your own comment
May 17th, 2024 12:21 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts