logo

Winos4.0 Malware Spread Through Game Apps Targets Education Sector

ID: bd098517-2e96-5a1f-847e-ec27996d7037

STIX ID: report--bd098517-2e96-5a1f-847e-ec27996d7037

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-11-08

Date Updated: 2026-04-22

Author: do son

...
...

FortiGuard Labs identified Winos4.0, a sophisticated modular malware framework (an evolution of Gh0strat) spread via malicious game-related applications that download encoded BMP/DLL payloads from domains like ad59t82g.com; Winos4.0 establishes persistence via the Windows RUN registry key, injects shellcode, loads additional modules from C2, and exfiltrates system information, clipboard contents, and crypto-wallet data (e.g., MetaMask, OKX).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.