Site navigation

“Cracked” Apps Are Poisoning Corporate Devices

Tom Quinn

,

malware
“Employees downloading free, unofficial or unlicensed software to their company devices represent a major security risk,” said Laila Mubashar, Barracuda.

As if CISOs don’t have enough threats to contend with, new research from Barracuda Networks has found a surge in employee downloads of illicit versions of software to their work devices, risking credential theft, infection, ransomware, and more.   

In what can only be described as a display of blissful ignorance, Barracuda’s Security Operations Centre detected multiple attempts by users to download pirated or “cracked” software, unauthorised versions of official software often tampered with to include malicious content. 

Because this illicit software can’t be patched or updated like legitimate versions, even benign security gaps remain wide open, but studies show that up to 80% or more of these programs come loaded with malware, compounding the risk.

Over the last month, Barracuda’s SOC repeatedly detected three types of suspicious executable files, namely activate.exe, activate.x86.exe and activate.x64.exe.  

While these might sound like generic filenames, not tied to any specific malware, they have been carefully chosen by hackers to sound legitimate and look routine, but are frequently seen in pirated and cracked software bundles, as well as phishing attachments, and fake software installers. 

Researchers found suspicious “activate” files sitting in Download folders, implying the user likely downloaded them themselves, knowingly or not, and were frequently opened manually soon after browser activity in Chrome or Microsoft Edge, and launched through explorer.exe, the Windows File Explorer. 

Together, these details suggest that the files were downloaded and opened during normal browsing, likely without users realising they were harmful. Barracuda added that these file names are often seen in cracked versions of Microsoft, Adobe and other work tools, with threat actors targeting employees looking for free, unlicensed tools for ease of access or cost savings.

To protect employees and assets from pirated or cracked software, Barracuda said that security teams should look out for major red flags, the foremost being manual interaction from a user to install and activate the program. 

Manual interaction, for instance, double‑clicking an application to install and run it, is unusual in modern tech stacks, where updates and installs are typically automated, giving defenders a clear behavioural sign that something is amiss.


Recommended reading


Security pros should also look to restrict local administrator rights and require approval for all software installations, allow only approved software to run on corporate devices, and monitor for executable files in Downloads and Temp folders.

“Employees downloading free, unofficial or unlicensed software to their company devices represent a major security risk, as they can become the entry points for serious security incidents,” said Laila Mubashar, senior cybersecurity analyst at Barracuda. 

“Organisations urgently need to put safeguards in place to protect employees from themselves. This should be centred on advanced, 24/7 security solutions, restricted permissions and user education.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data