logo

Massive Winos 4.0 Campaigns Target Taiwan

ID: 2906bc44-7054-5fce-85c8-dca8bdd913ed

STIX ID: report--2906bc44-7054-5fce-85c8-dca8bdd913ed

Feed Name: Fortinet Blog

Threat Score
80/100

Date Published: 2026-02-20

Date Updated: 2026-04-27

...
...

**Executive summary:** FortiGuard Labs observed multiple localized tax-themed phishing campaigns targeting organizations in Taiwan that deliver the Winos 4.0 (ValleyRat) remote-access malware and plugins via staged LNK downloaders and DLL sideloading, abusing a signed vulnerable driver (wsftprm.sys) for kernel privileges; the report includes detailed TTPs, IOCs (domains, IP 47.76.86.151, URLs, SHA256s), and attributes the activity to the Silver Fox APT subgroup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.