Hackers Impersonate Taiwan’s Tax Authority to Deploy Winos 4.0 Malware
ID: d3536523-7a1e-5449-be85-1dbd816799ea
STIX ID: report--d3536523-7a1e-5449-be85-1dbd816799ea
Feed Name: HackRead
FortiGuard Labs identified a January 2025 phishing campaign delivering a multi-stage Windows malware framework dubbed Winos 4.0 that impersonates Taiwan’s National Taxation Bureau; the campaign uses a malicious ZIP containing a fake application and DLLs which decrypt and execute shellcode, contact C2 servers, and deploy a core module that establishes persistence, bypasses UAC, harvests system information, captures screenshots and keystrokes, manipulates clipboard data, logs USB activity, and employs anti-sandbox and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
