Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Silver Fox APT uses malicious Winos 4.0 software in cyberats against Taiwanese organizations
Global Security

Silver Fox APT uses malicious Winos 4.0 software in cyberats against Taiwanese organizations

AdminBy AdminFebruary 27, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 27, 2025Red LakshmananCriminal software / intelligence threats

The new company focuses on the company in Taiwan with malicious software known as Winos 4.0 Within the framework of phishing emails, which are masked as the National Taxation Bureau of the country.

A company found last month’s Fortinet Fortiguard Labs, notes out of previous attack chains that used malicious apps related to games.

“The sender claimed that the malicious file was a list of enterprises planned for the tax inspection and asked the recipient to transfer the Treasury information,” the security researcher Pai Khan Liao – Note In a report that shared with Hacker News.

The investment is an official document of the Ministry of Finance, urging the recipient to load a list of enterprises planned for the tax inspection.

Cybersecurity

But in reality, the list is a Zip -Fail that contains malicious dll (“lastbld2base.dll”), which will laid the basis for the next stage of the attack, leading to the execution of Shellcode, which is responsible for loading the Winos 4.0 module from the remote server (“206.238.221 () 60”) for the collection.

The component described as an entry module, is able to do screenshots, write the keys, change the contents of the clipboard, monitor connected USB -devices, start Shellcode and allows you to perform sensitive actions (such as cmd.exe) when the safety with Kingsoft and Huorong will be displayed.

Fortinet said he also watched the second attack chain loading Internet Modul This can do screenshots WeChat and Internet Bank.

It is worth noting that A set of invading Distribution of malicious Winos 4.0 software has been assigned Monikers Void Arachne and Silver Fox, and malicious software is also overlapped Another Trojan Remote Access tracked as Valleyrat.

“They both come from one source: GH0St Rat, which was developed in China and opened in 2008,” said Daniel Dos Santos, Head of Security Studies at Vedere Freescout Lab, The Hacker News.

“Winos and Valleyrat are variations of the GH0St rats attributed to silver fox by various researchers at different times. Winos was a name that is commonly used in 2023 and 2024, while Valleyrat is now used.

ValleyratIt was first identified in early 2023, recently observed using counterfeit chrome sites as a pipeline to infect Chinese -speaking users. Similar boot schemes were also used to deliver GH0St rats.

In addition, the Attack Winos 4.0 chains included what is called Cleversoar’s mount, which is performed using a MSI installation package, distributed as fake software or game -related apps. Also fell with Winos 4.0 via Cleversoar is an open source code Nidhogg Rootkit.

Cybersecurity

“Cleversoar (…) installer checks the user language settings to make sure noted At the end of November 2024. “If the language is not recognized, the installer stops, effectively preventing the infection. This behavior strongly indicates that the actor threatens first and foremost focuses on victims in these regions.”

The disclosure of information occurs when Silver Fox APT was associated with a new company that uses the Training Players Dicom viewers to expand Valleyrat, which is then used to reset and cryptocurrencies on the victims. It is noteworthy that attacks use a vulnerable version Truesight driver To disable antivirus software.

“This company uses Dicom Treanized Viewers as Launches to Infect Victim Systems (Valleyrat) for remote access and control, key to capture the activity and powers of users, as well as a cry -to -use systemic resources for financial benefits,” the enterprise ” – Note.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.