This talk presents original threat research on a Russian military intelligence (GRU)-linked cyber espionage and disruption campaign very likely conducted by Sandworm (APT44), which has weaponized Ukraine's widespread use of pirated software. Since late 2023, Sandworm has distributed trojanized Microsoft KMS activators and fake Windows updates through Ukrainian-speaking torrent sites and forums, embedding malware directly into tools commonly used to bypass licensing restrictions. This social engineering strategy enabled precise targeting of economically vulnerable Ukrainian users – spanning civilians, businesses, and potentially government institutions – while evading conventional security controls.