Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

How to find AI chatbots on AdultFriendFinder

Michelle Phan tells Mashable how much VidCon has changed since she first attended

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Silver Fox Apt uses Winos 4.0 malware in cyberattacks against Taiwanese organizations
Celebrities

Silver Fox Apt uses Winos 4.0 malware in cyberattacks against Taiwanese organizations

By February 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 27, 2025Ravi LakshmananMalware/Threat Intelligence

The new campaign targets Taiwanese businesses using malware known as Winos 4.0 as part of a phishing email disguised as the country’s national tax office.

The campaign, detected last month by Fortinet Fortiguard Labs, shows a deviation from previous attack chains that leveraged malicious game-related applications.

“The sender claimed that the attached malicious files were a list of companies scheduled for tax inspections, and asked the recipient to transfer the information to the company’s treasurer,” security researcher Pay Han Riao said in a report shared with Hacker News.

This attachment mimics the official Treasury document and encourages recipients to download a list of companies scheduled for tax inspections.

Cybersecurity

But in reality, the list is a zip file containing the malicious dll (“lastbld2base.dll”) that lays the foundation for the next attack phase, leading to the execution of shellcode responsible for downloading Winos 4.0 modules from the remote server (“206.238.221[.]60”) To collect sensitive data.

A component called a login module can allow sensitive actions (such as cmd.exe) when screenshots, logging keystrokes, modifying clipboard content, monitoring connected USB devices, running shellcode, and when security prompts from Kingsoft Security and Huorong appear.

Fortinet also observed a second attack chain that downloads an online module that can capture screenshots of WeChat and online banks.

It is worth noting that Arachne and Silver Fox monikers are assigned to intrusion sets that distribute Winos 4.0 malware. The malware also overlaps with another remote access Trojan tracked as Valleyrat.

“Boths come from the same source: Gh0st rats developed in China and opened sourced in 2008,” Daniel Dos Santos, head of security research at Vedere Labs at Forescout, told Hacker News.

“Winos and Valleyrat are variations of GH0st rats due to Silver Fox by various researchers at various points. Winos was commonly used in 2023 and 2024, while valley rats are more commonly used.

Valleyrat, first identified in early 2023, was recently observed using fake chromium sites as a conduit that infects Chinese-speaking users. A similar drive-by download scheme has also been adopted to provide GH0st rats.

Additionally, the Winos 4.0 attack chain incorporates what is called the Cleversoar installer, which is run by MSI installer packages distributed as fake software or game-related applications. It is also dropped along with Winos 4.0 via Cleversoar.

Cybersecurity

“Cleversoar Installer […] Check your user’s language settings to see if it is set to Chinese or Vietnamese,” Rapid7 said in late November 2024. “If language is not recognized, the installer will terminate and effectively prevent infection. This action strongly suggests that threat actors are primarily targeting victims in these regions.”

This disclosure is made as Silver Fox Apt is linked to a new campaign that will leverage the Trojanized version of Philips DiCom Viewers to deploy ValleyRat. In particular, this attack has been found to disable antivirus software using a vulnerable version of the TrueSight driver.

“The campaign leverages lures to infect troilized DICOM viewers with victim systems to backdoors (ValleyRats) for remote access and control, keyloggers to capture user activity and credentials, and crypto miners who use system resources for financial gain,” Forescout said.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe US, the EU will move away as a deal with Russia with Ukrainian minerals in the eyes of Trump. News about the Russian Ukraine War
Next Article In the challenge of YouTube, Tiktok will revamp its desktop platform

Related Posts

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Zendaya & Tom Holland’s ‘Spider-Man’ Press Tour Couple Style

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How to find AI chatbots on AdultFriendFinder

Michelle Phan tells Mashable how much VidCon has changed since she first attended

The fastest-growing jobs in the creator economy aren’t in front of the camera.

Lee Suk-Quin explores the truth with new album “72RHR”

Trending Posts

Vote for Sombre, Phoebe Bridgers and more

June 26, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.