• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Reports Warn of Pirated Windows 10 ISOs Containing Dangerous Malware

T0@st

News Editor
Staff member
Joined
Mar 7, 2023
Messages
2,077 (4.75/day)
Location
South East, UK
According to a report published by Bleeping Computer last week and research conducted by the Doctor Web team, nefarious online organizations are distributing Windows 10 ISO files laced with extremely dangerous clipper malware variants. Microsoft ceased direct sales of licenses for its last gen operating system earlier this year, and a select bunch of folks are resorting to grabbing copies (for free) from pirate sources. The Doctor Web alert states: "(we) discovered a malicious clipper program in a number of unofficial Windows 10 builds that cybercriminals have been distributing via a torrent tracker. Dubbed Trojan.Clipper.231, this trojan app substitutes crypto wallet addresses in the clipboard with addresses provided by attackers. As of this moment, malicious actors have managed to steal cryptocurrency in an amount equivalent to about $19,000 (USD)."

It continues: "At the end of May 2023, a customer contacted Doctor Web with their suspicion that their Windows 10 computer was infected. The analysis our specialists carried out confirmed the presence of trojan applications in the system. These were Trojan.Clipper.231 stealer malware as well as the Trojan.MulDrop22.7578 dropper and Trojan.Inject4.57873 injector, which were used to launch the clipper. Doctor Web's virus laboratory successfully localized all these threats and neutralized them." It seems that hackers are hiding cryptocurrency hijackers within Extensible Firmware Interface (EFI) partitions, thus evading detection by antivirus software(s).





New Windows 10 licenses are still available to purchase from third-party retailers, and Microsoft does officially distribute W10 ISOs for existing customers—so it is odd that some system builders are relying on nefarious sources to "acquire" operating systems. TPU recommends using the official Windows 10 installation media tool, or a direct download of an ISO via non-Windows browser user agents—Bleeping Computer has detailed the methodology of mimicking a smartphone or tablet browser session here.

Doctor Web shared and warned that the following Windows builds as infected sources, but they anticipate that even more examples exist on torrents and other illegal distribution sites:
  • Windows 10 Pro 22H2 19045.2728 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 + Office 2021 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2846 x64 by BoJlIIIebnik RU.iso
  • Windows 10 Pro 22H2 19045.2913 + Office 2021 x64 by BoJlIIIebnik [RU, EN].iso
  • Windows 10 Pro 22H2 19045.2913 x64 by BoJlIIIebnik [RU, EN].iso

View at TechPowerUp Main Site | Source
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
23,412 (3.75/day)
Location
London,UK
System Name Codename: Icarus Mk.VI
Processor Intel 8600k@Stock -- pending tuning
Motherboard Asus ROG Strixx Z370-F
Cooling CPU: BeQuiet! Dark Rock Pro 4 {1xCorsair ML120 Pro|5xML140 Pro}
Memory 32GB XPG Gammix D10 {2x16GB}
Video Card(s) ASUS Dual Radeon™ RX 6700 XT OC Edition
Storage Samsung 970 Evo 512GB SSD (Boot)|WD SN770 (Gaming)|2x 3TB Toshiba DT01ACA300|2x 2TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White)
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Corsair AX760
Mouse Logitech G900
Keyboard Duckyshine Dead LED(s) III
Software Windows 10 Pro
Benchmark Scores (ノಠ益ಠ)ノ彡┻━┻
Man... I gave up with pirated copies of windows when i found out i could buy legit grey market windows keys for very very little money and the best part of grey market keys is microsoft doesnt even care if you bought it for the price of a chicken dinner and one or two beers. People who buy the keys for their own system builds arent their bread and butter. They are still making money off you regardless by selling your data :laugh:

Comedy Bang Bang Hello GIF by nounish ⌐◨-◨
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
25,967 (3.79/day)
Location
Alabama
System Name Rocinante
Processor I9 14900KS
Motherboard MSI MPG Z790I Edge WiFi Gaming
Cooling be quiet! Pure Loop 240mm
Memory 64GB Gskill Trident Z5 DDR5 6000 @6400
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 500GB 980 Pro | 1x 1TB 980 Pro | 1x 8TB Corsair MP400
Display(s) Odyssey OLED G9 (G95SC)
Case LANCOOL 205M MESH Snow
Audio Device(s) Moondrop S8's on Schiit Hel 2e
Power Supply ASUS ROG Loki SFX-L 1000W
Mouse Lamzu Atlantis mini (White)
Keyboard Monsgeek M3 Lavender, Akko Crystal Blues
VR HMD Quest 3
Software Windows 11
Benchmark Scores I dont have time for that.
nefarious online organizations are distributing Windows 10 ISO files laced with extremely dangerous clipper malware variants
Lol they have been doing that for years. It boggles my mind that people don’t expect it.
 
Joined
Jul 5, 2013
Messages
25,616 (6.45/day)
Man... I gave up with pirated copies of windows when i found out i could buy legit grey market windows keys for very very little money and the best part of grey market keys is microsoft doesnt even care if you bought it for the price of a chicken dinner and one or two beers. People who buy the keys for their own system builds arent their bread and butter. They are still making money off you regardless by selling your data :laugh:

Comedy Bang Bang Hello GIF by nounish ⌐◨-◨
The point of custom ISOs isn't the "free" aspect but rather the customized experiences that people want to use but don't know how to do for themselves. Piracy isn't really a problem in this situation but rather the makers of the bad ISO taking advantage of users wanting a better experience than that which microsoft has to offer.

In this situation, microsoft's own shenanigans are partly to blame. If they didn't include so much crap with Windows and weren't such goose-steppers where certain configurations were concerned, the custom ISO community wouldn't exist the way it does currently because the need would not exist.

Lol they have been doing that for years. It boggles my mind that people don’t expect it.
That's because it's not as common as one might expect. Most customized Windows ISOs are safe because the groups that make them have a reputation to protect. There are always bad actors though..

EDIT: @Solaris17 You can laugh, but it's one of my job duties to regularly check for this kind of thing and write reports detailing the findings. This is one of the reasons I'm so ultra-cautious about system security and why I DON'T trust microsoft to keep things "safe". Their definition and brand of "safe" is usually anything but fully secure.
 
Last edited:

Keullo-e

S.T.A.R.S.
Joined
Dec 16, 2012
Messages
11,184 (2.68/day)
Location
Finland
System Name 4K-gaming
Processor AMD Ryzen 7 5800X
Motherboard Gigabyte B550M Aorus Elite
Cooling Eisbaer 240 + 140, EK Vector TUF
Memory 32GB Kingston HyperX Fury @ DDR4-3466
Video Card(s) Asus TUF RTX 3080 10GB OC
Storage ~4TB SSD + 6TB HDD
Display(s) Acer XV273K 4K120 + Lenovo L32p-30 4K60
Case Corsair 4000D Airflow White
Audio Device(s) Asus TUF H3 Wireless
Power Supply EVGA Supernova G2 750W
Mouse Logitech MX518 + Asus TUF P1 mousepad
Keyboard Roccat Vulcan 121 AIMO
VR HMD Oculus Rift CV1
Software Windows 11 Pro
Benchmark Scores It runs Crysis remastered at 4K
Just wondering that who uses those when you can get a legit .iso from MS itself?
 
Joined
Jul 5, 2013
Messages
25,616 (6.45/day)
Note that "other" follows "torrent."
Exactly. The way that statement is written directly implies that torrents are illegal, which is incorrect.

Just wondering that who uses those when you can get a legit .iso from MS itself?
In the case of the article subject ISOs, mostly Russians as microsoft has put strict limitations on downloads from within Russia and it's ally nations.
 

Keullo-e

S.T.A.R.S.
Joined
Dec 16, 2012
Messages
11,184 (2.68/day)
Location
Finland
System Name 4K-gaming
Processor AMD Ryzen 7 5800X
Motherboard Gigabyte B550M Aorus Elite
Cooling Eisbaer 240 + 140, EK Vector TUF
Memory 32GB Kingston HyperX Fury @ DDR4-3466
Video Card(s) Asus TUF RTX 3080 10GB OC
Storage ~4TB SSD + 6TB HDD
Display(s) Acer XV273K 4K120 + Lenovo L32p-30 4K60
Case Corsair 4000D Airflow White
Audio Device(s) Asus TUF H3 Wireless
Power Supply EVGA Supernova G2 750W
Mouse Logitech MX518 + Asus TUF P1 mousepad
Keyboard Roccat Vulcan 121 AIMO
VR HMD Oculus Rift CV1
Software Windows 11 Pro
Benchmark Scores It runs Crysis remastered at 4K
In the case of the article subject ISOs, mostly Russians as microsoft has put strict limitations on downloads from within Russia and it's ally nations.
Ah, good point there. Yet still weird if there isn't a way (at least an easy one) to get a legit iso for them.
 

T0@st

News Editor
Staff member
Joined
Mar 7, 2023
Messages
2,077 (4.75/day)
Location
South East, UK
Exactly. The way that statement is written directly implies that torrents are illegal, which is incorrect.
It is grey area, given that certain ISPs and governments have blocked access to torrent listings and program functionality.
 
Joined
Jul 5, 2013
Messages
25,616 (6.45/day)
Ah, good point there. Yet still weird if there isn't a way (at least an easy one) to get a legit iso for them.
One would think microsoft would make a choice that is logical and reasonable, but alas...

It is grey area, given that certain ISPs and governments have blocked access to torrent listings and program functionality.
In some places, maybe, but not everywhere and not most places. Regardless, it's still poorly worded/stated.
 
Joined
Mar 10, 2010
Messages
11,878 (2.29/day)
Location
Manchester uk
System Name RyzenGtEvo/ Asus strix scar II
Processor Amd R5 5900X/ Intel 8750H
Motherboard Crosshair hero8 impact/Asus
Cooling 360EK extreme rad+ 360$EK slim all push, cpu ek suprim Gpu full cover all EK
Memory Corsair Vengeance Rgb pro 3600cas14 16Gb in four sticks./16Gb/16GB
Video Card(s) Powercolour RX7900XT Reference/Rtx 2060
Storage Silicon power 2TB nvme/8Tb external/1Tb samsung Evo nvme 2Tb sata ssd/1Tb nvme
Display(s) Samsung UAE28"850R 4k freesync.dell shiter
Case Lianli 011 dynamic/strix scar2
Audio Device(s) Xfi creative 7.1 on board ,Yamaha dts av setup, corsair void pro headset
Power Supply corsair 1200Hxi/Asus stock
Mouse Roccat Kova/ Logitech G wireless
Keyboard Roccat Aimo 120
VR HMD Oculus rift
Software Win 10 Pro
Benchmark Scores 8726 vega 3dmark timespy/ laptop Timespy 6506
It is grey area, given that certain ISPs and governments have blocked access to torrent listings and program functionality.
Certain countries block access to tiktok does that make it a grey area?.(I'd ban it worldwide tbf)

Torrents do often involve illegality but it's not exclusive and some use them legitimately.

The same Could be said of the whole internet really, it's a path to evil ban it.

I too don't think you should be spouting a few governments party line(torrent bad)

It's the stupidest bit of news I've seen today given the security environment present, wtaf expects safe and sound OS, IF you're dodging paying.
I get custom iso"s but a legit key can make them legit and possibly safe, but again no guarantee, and too risky for me.
 
Joined
Dec 26, 2006
Messages
3,564 (0.56/day)
Location
Northern Ontario Canada
Processor Ryzen 5700x
Motherboard Gigabyte X570S Aero G R1.1 BiosF5g
Cooling Noctua NH-C12P SE14 w/ NF-A15 HS-PWM Fan 1500rpm
Memory Micron DDR4-3200 2x32GB D.S. D.R. (CT2K32G4DFD832A)
Video Card(s) AMD RX 6800 - Asus Tuf
Storage Kingston KC3000 1TB & 2TB & 4TB Corsair LPX
Display(s) LG 27UL550-W (27" 4k)
Case Be Quiet Pure Base 600 (no window)
Audio Device(s) Realtek ALC1220-VB
Power Supply SuperFlower Leadex V Gold Pro 850W ATX Ver2.52
Mouse Mionix Naos Pro
Keyboard Corsair Strafe with browns
Software W10 22H2 Pro x64
Windows……the OS that ‘keeps an eye on you’
 
Joined
May 19, 2009
Messages
1,827 (0.33/day)
Location
Latvia
System Name Personal \\ Work - HP EliteBook 840 G6
Processor 7700X \\ i7-8565U
Motherboard Asrock X670E PG Lightning
Cooling Noctua DH-15
Memory G.SKILL Trident Z5 RGB Black 32GB 6000MHz CL36 \\ 16GB DDR4-2400
Video Card(s) ASUS RoG Strix 1070 Ti \\ Intel UHD Graphics 620
Storage 2x KC3000 2TB, Samsung 970 EVO 512GB \\ OEM 256GB NVMe SSD
Display(s) BenQ XL2411Z \\ FullHD + 2x HP Z24i external screens via docking station
Case Fractal Design Define Arc Midi R2 with window
Audio Device(s) Realtek ALC1150 with Logitech Z533
Power Supply Corsair AX860i
Mouse Logitech G502
Keyboard Corsair K55 RGB PRO
Software Windows 11 \\ Windows 10
In case anyone here has trouble understanding what "BoJlIIIebnik" means - magician/wizard.

Ahhh, reminds me of the good times of stuff like "Windows XP BLACK EDITION" . :laugh:
 
Joined
Mar 9, 2021
Messages
306 (0.26/day)
System Name Back in Black
Processor Ryzen 5 3600
Motherboard MSI B450 Tomahawk
Cooling ID-Cooling SE-224-XT Black
Memory Corsair Vengeance LPX 16GB (2x8) 3000mhz C15
Video Card(s) Asus Rog Strix GTX 1070 TI Advanced Edition
Storage Crucial MX500 500GB / Solidigm P41 Plus 1TB
Display(s) Samsung 32" TV 1080p
Case Montech Air X Black
Power Supply Thermaltake Toughpower GF1 750W Gold
Mouse Redragon M711 Cobra
Keyboard Corsair K55
Note that "other" follows "torrent."
Understandable, but if you say "John and other students", it implies John is a student as well.

In this case, the correct use would be "torrents and illegal distribution sites".
 
Joined
Jan 18, 2020
Messages
691 (0.44/day)
An OEM key is so cheap, I don't understand the need to get a pirated Iso these days;

**And no OEM keys are not illegal!

Cheaper than $0 ?

We've always got Linux as well for $0, value.

Frankly Windows has been getting worse for about 15 years and the sooner we get mass adoption of an alternative , like Android for desktop or similar friendly Linux based OS, the better the world of computing will be. In fact, I'd say Microsoft hasn't produced a decent product generally for a similar time frame.

All they've done is made worse versions of existing software and gone SAAS, cloud, Azure, 365 ,Windows 10/11, and charge for them monthly, more $ for worse products.
 
Joined
Oct 6, 2021
Messages
1,481 (1.55/day)
Cheaper than $0 ?

We've always got Linux as well for $0, value.

Frankly Windows has been getting worse for about 15 years and the sooner we get mass adoption of an alternative , like Android for desktop or similar friendly Linux based OS, the better the world of computing will be. In fact, I'd say Microsoft hasn't produced a decent product generally for a similar time frame.

All they've done is made worse versions of existing software and gone SAAS, cloud, Azure, 365 ,Windows 10/11, and charge for them monthly, more $ for worse products.
I completely understand the criticism, I agree that after Windows 7 it got worse and worse, full of unnecessary software and excessive telemetry.

But no, Linux is not an alternative to Windows for most people, neither in practicality of use nor in terms of compatibility. People have less time every day and I'm sorry but when I get my PC I just want things to work.
 
Joined
May 19, 2009
Messages
1,827 (0.33/day)
Location
Latvia
System Name Personal \\ Work - HP EliteBook 840 G6
Processor 7700X \\ i7-8565U
Motherboard Asrock X670E PG Lightning
Cooling Noctua DH-15
Memory G.SKILL Trident Z5 RGB Black 32GB 6000MHz CL36 \\ 16GB DDR4-2400
Video Card(s) ASUS RoG Strix 1070 Ti \\ Intel UHD Graphics 620
Storage 2x KC3000 2TB, Samsung 970 EVO 512GB \\ OEM 256GB NVMe SSD
Display(s) BenQ XL2411Z \\ FullHD + 2x HP Z24i external screens via docking station
Case Fractal Design Define Arc Midi R2 with window
Audio Device(s) Realtek ALC1150 with Logitech Z533
Power Supply Corsair AX860i
Mouse Logitech G502
Keyboard Corsair K55 RGB PRO
Software Windows 11 \\ Windows 10
Which one? There were a bunch! The version that became "Integral Edition" was perfectly clean(safe) and was very well done.
Short answer is "Yes", or all of them. Was hard to choose when I was little and dowload speeds were... not great.
 
Top