Chinese-speaking users are targets of an unusual malicious campaign, called Void Arachne.

This campaign uses malicious Windows Installer (MSI) files for virtual private networks (VPNs) to deliver a command and control (C&C) framework called Winos 4.0.
Read more: Markopolo scam targets crypto users
“The campaign also promotes infected MSI files containing nude, deepfake pornography creation software, as well as AI voice and face technologies,” Trend Micro researchers Peter Girnus, Aliakbar Zahravi, and Ahmed Mohamed Ibrahim wrote in a technical report published today. “The campaign uses poisoning tactics on SEO and social and messaging platforms to distribute malware.”
The cybersecurity firm , which discovered the new threat group in early April 2024, said the attacks include advertising popular software such as Google Chrome , LetsVPN, QuickVPN, and a Telegram language pack for Simplified Chinese, to distribute Winos. Alternative attack chains use backdoored installers distributed in Chinese-themed Telegram channels
The links that appear through black hat SEO tactics point to a special infrastructure created by the adversary to distribute the installations in the form of ZIP files. As for the attacks targeting Telegram channels, the MSI installers and ZIP files are hosted directly on the messaging platform.
The use of a malicious Chinese language pack is particularly interesting, as it creates a huge attack surface. Other software seeks to offer capabilities to create non-consensual deepfake porn videos for sex ransom scams, AI technologies for virtual kidnappings, as well as voice and face-swapping tools.
The installers are designed to modify firewall rules, allowing inbound and outbound traffic related to malware when devices are connected to public networks.
Additionally, it drops a loader that decrypts and executes a second-stage payload in memory. This then triggers a Visual Basic (VBS) script to install persistence on the computer and execute an unknown batch script, delivering the Winos 4.0 C&C framework through a stage that establishes C&C communications with a remote server.
See also: Deepfake scams have cost companies millions
Winos 4.0, written in C++, is equipped for file management, denial of service (DDoS) attacks via TCP/UDP/ICMP/HTTP, disk searching, webcam control, screenshot capture, microphone recording, keystroke logging, and remote shell access.
The backdoor is enhanced by a plugin, which achieves the aforementioned capabilities through a set of 23 exclusive components for 32- and 64-bit variants. Furthermore, it can be further extended with external plugins integrated by threat actors themselves, according to their needs.
The core Winos component also includes methods to detect the presence of security software prevalent in China, while acting as the main “orchestrator” for adding, purging system logs, and downloading and executing additional payloads from a specified URL.
"Internet connectivity in the People's Republic of China is tightly controlled through a combination of legislative measures and technological controls, collectively known as the 'Great Firewall of China,'" the researchers note.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Read also: Deepfake: How does it work and how to detect fake content?
"Due to tight government control, the demand for VPN and public interest in this technology have increased significantly. This, in turn, has attracted the attention of threat actors, who seek to exploit the increased need for software capable of bypassing the Great Firewall and Internet censorship."
Source: thehackernews
