logo

Hackers Impersonate Taiwan’s Tax Authority to Deploy Winos 4.0 Malware

ID: d3536523-7a1e-5449-be85-1dbd816799ea

STIX ID: report--d3536523-7a1e-5449-be85-1dbd816799ea

Feed Name: HackRead

Threat Score
74/100

Date Published: 2025-02-27

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

FortiGuard Labs identified a January 2025 phishing campaign delivering a multi-stage Windows malware framework dubbed Winos 4.0 that impersonates Taiwan’s National Taxation Bureau; the campaign uses a malicious ZIP containing a fake application and DLLs which decrypt and execute shellcode, contact C2 servers, and deploy a core module that establishes persistence, bypasses UAC, harvests system information, captures screenshots and keystrokes, manipulates clipboard data, logs USB activity, and employs anti-sandbox and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.