Winos4.0 Malware Spread Through Game Apps Targets Education Sector
ID: bd098517-2e96-5a1f-847e-ec27996d7037
STIX ID: report--bd098517-2e96-5a1f-847e-ec27996d7037
Feed Name: securityonline.info
Threat Score
FortiGuard Labs identified Winos4.0, a sophisticated modular malware framework (an evolution of Gh0strat) spread via malicious game-related applications that download encoded BMP/DLL payloads from domains like ad59t82g.com; Winos4.0 establishes persistence via the Windows RUN registry key, injects shellcode, loads additional modules from C2, and exfiltrates system information, clipboard contents, and crypto-wallet data (e.g., MetaMask, OKX).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
