Winos4.0 abuses gaming apps to infect, control Windows machines
ID: 0af05a8e-067f-5442-9d2c-c2aa7bc38cb7
STIX ID: report--0af05a8e-067f-5442-9d2c-c2aa7bc38cb7
Feed Name: The Register (Security)
Criminals are distributing a multi-stage Windows malware framework named Winos4.0 hidden in game installers and optimization utilities; the attack chain uses staged DLLs and shellcode to establish persistence (registry storage), perform reconnaissance and data theft (screenshots, documents, wallet extensions), and maintain a C2 backdoor. Fortinet links the malware to multiple campaigns including activity associated with the Silver Fox group, and warns users to obtain applications from trusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
