logo

Winos4.0 abuses gaming apps to infect, control Windows machines

ID: 0af05a8e-067f-5442-9d2c-c2aa7bc38cb7

STIX ID: report--0af05a8e-067f-5442-9d2c-c2aa7bc38cb7

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-11-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Criminals are distributing a multi-stage Windows malware framework named Winos4.0 hidden in game installers and optimization utilities; the attack chain uses staged DLLs and shellcode to establish persistence (registry storage), perform reconnaissance and data theft (screenshots, documents, wallet extensions), and maintain a C2 backdoor. Fortinet links the malware to multiple campaigns including activity associated with the Silver Fox group, and warns users to obtain applications from trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.