logo

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

ID: 068b01c2-50cc-5f6b-b7ea-a021f28e5a77

STIX ID: report--068b01c2-50cc-5f6b-b7ea-a021f28e5a77

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

FortiGuard Labs reports a January 2025 Winos4.0 campaign targeting organizations in Taiwan via phishing emails that impersonate tax authorities; malicious PDFs and attached ZIPs drop a multi-stage loader (e.g., 20250109.exe/ApowerREC.exe) which decrypts shellcode, performs sandbox detection, stores encrypted modules in the registry, disables UAC and security products, performs clipboard hijacking, keylogging and lateral movement, and contacts C2 infrastructure. The analysis provides IoCs (filenames, registry keys, mutex names, C2 domain), describes anti-forensic and anti-analysis techniques, and recommends controls such as CDR on email gateways, registry monitoring for UAC changes, behavioral detection, and application allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.