Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs
Global Security

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

AdminBy AdminJune 17, 2025No Comments3 Mins Read
Gh0stCringe and HoldingHands RAT Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 17, 2025Red LakshmananMalicious software / email safety

GH0Stcringe and Holdinghands rats malicious programs

Cybersecurity researchers warn of a new phishing campaign aimed at Taiwan with family malware such as HoldingHands Rat and GH0Stcringe.

Activities is part of a wider company that delivered Winos 4.0 Frames Malicious Programs in early January in Sending Phisching Messages By betraying the National Taxation Bureau of Taiwan, the Fortinet Fortinet Lab – Note In a report that shared with Hacker News.

Cybersecurity

Cybersecurity company said it had discovered additional samples of malicious programs through permanent monitoring, and that she watched the same actor threats called Silver Fox APT, using PDF documents located on malicious programs, or postal files distributed through phisching to deliver GH0Stcrige Rats Holdinghands.

It is worth noting that both Holdinghands Rat (he’s gh0stbins) and Gh0stcringe are variants of the famous Trojan remote access called GH0St Rat, which is widely used by Chinese hacking groups.

A silver fox that is suitable for Taiwan

The starting point of the attack is a phishing email masking as a government’s or business partners that use taxes, accounts and pensions to convince the recipients in the opening of the attachment. Alternative attack chains have been found to use a built -in image that loads malicious software when pressed.

PDF files, in turn, contain a link that redirects the promising goals to the download page that places the ZIP archive. The file contains several legitimate executable files, shellcode loaders and encrypted Shellcode.

A multi -stage infection sequence entails the use of shellcode forklifts to decrypt and perform Shellcode, which is nothing but DLL files, downloaded by legitimate binary files using DLL download methods. Intermediate loads, deployed under the attack, include anti-VM and escalation of privileges to ensure that malicious software works freely on the compromised host.

Cybersecurity

The attack is completed by the execution of “msgdb.dat”, which implements team and control features (C2) to collect user information and download additional modules to facilitate file control and the ability to remove desktop.

Fortinet said he also found that the actor threats that distribute GH0Stcringe by PDF attachments in phishing emails to users to document HTM pages.

“Network of the attacks consists of numerous Shellcode fragments and loaders, making the Attack Flow Complex,” the company said. “In various winds, holdings and GH0Stcringe, this group of threats constantly develop their strategies for malware and distribution.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.