logo

New Threat Actor 'Void Arachne' Targets Chinese Users with Malicious VPN Installers

ID: 84a16223-0506-5295-a0a8-a2932be9e57b

STIX ID: report--84a16223-0506-5295-a0a8-a2932be9e57b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-19

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

**Void Arachne** is a campaign targeting Chinese-speaking users that uses malicious MSI installers (posed as VPNs, language packs, and deepfake/AI tools) distributed via SEO poisoning and messaging platforms to deploy the Winos 4.0 backdoor — a plugin-based C++ implant capable of DDoS, keylogging, webcam/microphone capture, remote shell, persistence, and evasion; follow-up analysis links active abuse to an actor tracked as Silver Fox.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.