logo

Threat Campaign Spreads Winos4.0 Through Game Application

ID: fa2437fa-823b-524a-9c6d-e229124bab3b

STIX ID: report--fa2437fa-823b-524a-9c6d-e229124bab3b

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2024-11-06

Date Updated: 2026-04-27

...
...

Winos4.0 is an advanced, modular Windows malware framework deployed via malicious game-related installers and optimization tools; the report details a multi-stage infection (XOR-decoded payloads, DLL loaders, shellcode, online and login modules), persistence mechanisms (registry Run entry, scheduled task), C2 infrastructure (ad59t82g.com, 202.79.173.4), capabilities (system/clipboard collection, screenshot and document exfiltration, crypto-extension checks), and provides IoCs and Fortinet detections to help defenders block and remediate the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.