logo

'HoldingHands' Acts Like a Pickpocket With Taiwan Orgs

ID: c2d59eb6-b301-514f-8681-2230144030a3

STIX ID: report--c2d59eb6-b301-514f-8681-2230144030a3

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-06-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A sophisticated, ongoing phishing campaign targeting Taiwanese organizations uses tax- and government-themed lures and malicious ZIP attachments (containing files such as dokan2.dll, dxpi.txt, and MsgDb.dat) to deploy multistage malware — notably Winos 4.0, HoldingHands (Gh0stBins), and Gh0stCringe — for data theft, surveillance, and C2 activity; Fortinet has tracked the activity since January and reporting links it to a broader pattern of regionally focused, potentially state‑backed operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.