logo

Hackers increasingly use Winos4.0 post-exploitation kit in attacks

ID: 2a40919a-47b9-5c9b-ad36-e069c6b839fa

STIX ID: report--2a40919a-47b9-5c9b-ad36-e069c6b839fa

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report documents the Winos4.0 post-exploitation framework being distributed through seemingly legitimate game-related installers targeting Chinese users; the malware uses multi-stage DLL loaders and registry persistence, establishes C2 connections, and includes modules that gather system info, check for security products, steal data (screenshots, clipboard contents, documents) and harvest cryptocurrency wallet extension data. Fortinet and Trend Micro provide detailed analysis and IoCs, and attackers tracked as Void Arachne/Silver Fox are associated with these campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.