Threat Campaign Spreads Winos4.0 Through Game Application
ID: fa2437fa-823b-524a-9c6d-e229124bab3b
STIX ID: report--fa2437fa-823b-524a-9c6d-e229124bab3b
Feed Name: Fortinet Blog
Winos4.0 is an advanced, modular Windows malware framework deployed via malicious game-related installers and optimization tools; the report details a multi-stage infection (XOR-decoded payloads, DLL loaders, shellcode, online and login modules), persistence mechanisms (registry Run entry, scheduled task), C2 infrastructure (ad59t82g.com, 202.79.173.4), capabilities (system/clipboard collection, screenshot and document exfiltration, crypto-extension checks), and provides IoCs and Fortinet detections to help defenders block and remediate the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
