Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » New Winos 4.0 Malware Infects Gamers With Game Optimization Malware
Global Security

New Winos 4.0 Malware Infects Gamers With Game Optimization Malware

AdminBy AdminNovember 6, 2024No Comments3 Mins Read
Game Optimization Apps
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 6, 2024Ravi LakshmananMalware / Internet Security

Applications for optimization of games

Cybersecurity researchers warn that a command and control (C&C) system called Vinos distributed in game-related applications such as installers, speed boosters, and optimization utilities.

“Winos 4.0 is an advanced malware framework that offers comprehensive functionality, a stable architecture, and effective control over multiple online endpoints for further action.” – Fortinet FortiGuard Labs said in a report shared with The Hacker News. “Rebuilt from v Gh0st RATit includes several modular components, each of which performs a different function.’

Winos 4.0 distribution campaigns were documented in June by Trend Micro and the KnownSec 404 team. Cybersecurity companies are tracking a cluster of activity called Void Arachne and Silver Fox.

Cyber ​​security

Attacks on Chinese-speaking users have been observed using search engine optimization (SEO) tactics, social media and messaging platforms such as Telegram to spread malware.

Fortinet’s latest analysis shows that users who end up running game-related malware run a multi-step infection process that begins by receiving a fake BMP file from a remote server (“ad59t82g(.)com”), which is then decoded into a dynamic -link library (DLL).

The DLL takes care of setting up the runtime environment by downloading three files from the same server: t3d.tmp, t4d.tmp, and t5d.tmp, the first two of which are then unpacked to produce the next set of payloads that comprise the executable. (“u72kOdQ.exe”) and three DLL files, including “libcef.dll.”

Applications for optimization of games

“The DLL is called ‘学籍电视’, which stands for ‘Student Registration System,’ which suggests that the threat actor may be targeting educational organizations,” Fortinet said.

In the next step, the binary is used to load “libcef.dll”, which then extracts and executes the second step shellcode from t5d.tmp. The malware establishes contact with its command-and-control (C2) server (“202.79.173(.)4” using the TCP protocol) and obtains another DLL (“上线设计.dll”).

A third-tier DLL, part of Winos 4.0, downloads encoded data from the C2 server, a fresh DLL module (“பிர்கும் மாட்டு.dll”) responsible for collecting system information, copying clipboard contents, collecting data from cryptocurrency wallet extensions such as OKX Wallet and MetaMask, as well as facilitating backdoor functionality by waiting for further commands from the server.

Cyber ​​security

Winos 4.0 also allows the delivery of additional plugins from the C2 server that allow you to take screenshots and download sensitive documents from a compromised system.

“Winos4.0 is a powerful framework similar to Cobalt Strike and Sliver that can support multiple functions and easily monitor compromised systems,” Fortinet said. “Threat companies use game-related applications to lure victims into downloading and running malicious software without caution and successfully deploy deep system checks.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.