HomeSecurityHackers infect Windows devices with Winos4.0 framework

Hackers infect Windows devices with Winos4.0 framework

Hackers are targeting Windows users with the malicious Winos4.0 framework , which is distributed through seemingly legitimate applications gaming-related .

Hackers infect Windows devices with Winos4.0 framework

Winos4.0 is a toolkit that was documented by Trend Micro last summer in a report on attacks against Chinese users. At the time, a group tracked as Void Arachne/Silver Fox lured victims using various useful software (VPN, Google Chrome browser) as bait. They were modified for the Chinese market, but came with a malicious component.

Now, Fortinet is seeing a shift in malicious activity, noting that hackers are now relying on games and game-related files. They continue to target Chinese users.

See also: HookBot malware imitates popular brands

When the seemingly legitimate installers are run, a DLL file is downloaded from “ad59t82g[.]com.” This begins a multi-stage infection.

In the first stage, a DLL file (you.dll) downloads additional files, sets up the execution environment, and establishes persistence by adding entries to the Windows Registry.

In the second stage, the injected shellcode loads APIs, retrieves configuration data , and establishes a connection to the command and control (C2) server.

In the third stage, another DLL (上线支持.dll) appears, which retrieves additional configuration data from the C2 server, stores it in the registry at “HKEY_CURRENT_USER\Console\0” and updates the C2 addresses.

See also: FakeCall malware redirects banking calls to attackers

Finally, in the fourth stage, the login module (简体选择支架.dll) is loaded onto the victim 's machine , which performs the main malicious actions :

hackers Winos4.0 Windows games
Hackers infect Windows devices with Winos4.0 framework
  • Collects system and environmental information (e.g. IP address, operating system details, CPU).
  • Checks for any antivirus and monitoring software.
  • It collects data for specific cryptocurrency wallet extensions.
  • It maintains a persistent backdoor to the C2 server. This allows the attacker to issue commands and retrieve additional data.
  • It steals data and documents, takes screenshots, and monitors for changes to the clipboard.

As mentioned earlier, Winos4.0 checks for antivirus software. It checks for companies like Kaspersky, Avast, Avira, Symantec, Bitdefender, Dr.Web, Malwarebytes, McAfee, AhnLab, ESET, Panda Security, and Microsoft Security Essentials. It adjusts its behavior based on what it finds and can stop it from running.

See also: US: Charges against Russian for creating RedLine malware

According to researchers, hackers have been using the Winos4.0 framework for several months, and the emergence of new campaigns with game-related baits shows that the attacks are evolving.

Fortinet describes Winos4.0 as a powerful framework that can be used to audit compromised systems. Indicators of Compromise (IoC) are available in Fortinet and Trend Micro.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Users are advised to remain vigilant by avoiding downloading games, apps and files from untrusted sources and ensuring that their antivirus software is up to date. Cybersecurity experts are urging users to adopt safer internet practices and stay informed about emerging threats.

Another important security practice is to regularly update the operating system and all applications and software used to patch any known vulnerabilities.

Additionally, implementing strong passwords and two-factor authentication is essential . Hackers often gain access through weak passwords.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS