The CMWTAT website has now restored its legitimate download links. However, cmwtat.cloudmoe.com was previously compromised, and the download links to the Alibaba Cloud and Amazon Cloud mirrors were replaced with ZIP files containing malicious .msi installers. Downloads from GitHub Releases are not confirmed to be affected by this incident.
According to my investigation, the attacker had been scanning the server for some time, and the actual intrusion most likely began on the evening of August 29, 2026. The exact time when the malware was uploaded is still under investigation. The file timestamps on the server were also falsified to show dates in 2025.
A normal CMWTAT download should be a standalone .exe file, or a ZIP archive containing only one .exe file. If a ZIP archive contains an .msi file, do not run it.
If you have already run a suspicious file, immediately perform a full scan with up-to-date antivirus software, back up your important data, and reinstall the operating system if possible. Deleting CMWTAT will not affect an activation that has already been completed, and the system will activate automatically after reinstallation.
Thanks to @efojug for reporting this issue in Issue #115.
I sincerely apologize for the inconvenience and risks caused by this incident. I will continue investigating the details of the attack and take greater care to ensure the security of the server, in order to prevent similar incidents from happening again.