Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

How a hardware wallet protects your private key: Security and safety instructions

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Review Week: Meta reveals Oakley Smart Glasses

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Silver Fox Apt uses Winos 4.0 malware in cyberattacks against Taiwanese organizations
Identity

Silver Fox Apt uses Winos 4.0 malware in cyberattacks against Taiwanese organizations

userBy userFebruary 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 27, 2025Ravi LakshmananMalware/Threat Intelligence

The new campaign targets Taiwanese businesses using malware known as Winos 4.0 as part of a phishing email disguised as the country’s national tax office.

The campaign, detected last month by Fortinet Fortiguard Labs, shows a deviation from previous attack chains that leveraged malicious game-related applications.

“The sender claimed that the attached malicious files were a list of companies scheduled for tax inspections, and asked the recipient to transfer the information to the company’s treasurer,” security researcher Pay Han Riao said in a report shared with Hacker News.

This attachment mimics the official Treasury document and encourages recipients to download a list of companies scheduled for tax inspections.

Cybersecurity

But in reality, the list is a zip file containing the malicious dll (“lastbld2base.dll”) that lays the foundation for the next attack phase, leading to the execution of shellcode responsible for downloading Winos 4.0 modules from the remote server (“206.238.221[.]60”) To collect sensitive data.

A component called a login module can allow sensitive actions (such as cmd.exe) when screenshots, logging keystrokes, modifying clipboard content, monitoring connected USB devices, running shellcode, and when security prompts from Kingsoft Security and Huorong appear.

Fortinet also observed a second attack chain that downloads an online module that can capture screenshots of WeChat and online banks.

It is worth noting that Arachne and Silver Fox monikers are assigned to intrusion sets that distribute Winos 4.0 malware. The malware also overlaps with another remote access Trojan tracked as Valleyrat.

“Boths come from the same source: Gh0st rats developed in China and opened sourced in 2008,” Daniel Dos Santos, head of security research at Vedere Labs at Forescout, told Hacker News.

“Winos and Valleyrat are variations of GH0st rats due to Silver Fox by various researchers at various points. Winos was commonly used in 2023 and 2024, while valley rats are more commonly used.

Valleyrat, first identified in early 2023, was recently observed using fake chromium sites as a conduit that infects Chinese-speaking users. A similar drive-by download scheme has also been adopted to provide GH0st rats.

Additionally, the Winos 4.0 attack chain incorporates what is called the Cleversoar installer, which is run by MSI installer packages distributed as fake software or game-related applications. It is also dropped along with Winos 4.0 via Cleversoar.

Cybersecurity

“Cleversoar Installer […] Check your user’s language settings to see if it is set to Chinese or Vietnamese,” Rapid7 said in late November 2024. “If language is not recognized, the installer will terminate and effectively prevent infection. This action strongly suggests that threat actors are primarily targeting victims in these regions.”

This disclosure is made as Silver Fox Apt is linked to a new campaign that will leverage the Trojanized version of Philips DiCom Viewers to deploy ValleyRat. In particular, this attack has been found to disable antivirus software using a vulnerable version of the TrueSight driver.

“The campaign leverages lures to infect troilized DICOM viewers with victim systems to backdoors (ValleyRats) for remote access and control, keyloggers to capture user activity and credentials, and crypto miners who use system resources for financial gain,” Forescout said.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe US, the EU will move away as a deal with Russia with Ukrainian minerals in the eyes of Trump. News about the Russian Ukraine War
Next Article In the challenge of YouTube, Tiktok will revamp its desktop platform
user
  • Website

Related Posts

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

June 21, 2025

Qilin ransomware adds “Cole Lawyer” feature that puts pressure on victims for larger ransoms

June 20, 2025

Television in Iranian states hijacked mid-distance broadcasts amid geopolitical tensions. $90 million stolen from Crypto Heist

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How a hardware wallet protects your private key: Security and safety instructions

Cartoonist Paul Pope is more worried about killer robots than AI plagiarism

Review Week: Meta reveals Oakley Smart Glasses

Spiders scattered behind M&S and cooperative cyberattacks, with up to $592 million in damages

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

How a hardware wallet protects your private key: Security and safety instructions

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Apple is talking to you to win AI startup confusion

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.