Seems like a pirated .iso would be a great place to deliver malicious code to Ring 0, hiding itself from the kernel and becoming essentially impossible to detect from the infected OS itself. I'm sure botnet creators are already well aware of this.
Are people insane?
I might not have ultimate faith in Microsoft, but comparatively I have zero faith (and a lot of suspicion) of what are essentially bands of thieves among piracy groups.
I engaged in casual piracy when I was a teen out of necessity, though I never felt the need to invent justifications. In my adult life, though...pirating executables is the domain of the naive or the ridiculously trustworthy.