HomeSecurityFake installers for LetsVPN & QQ Browser distribute Winos 4.0 malware

Fake installers for LetsVPN & QQ Browser distribute Winos 4.0 malware

According to a report by Rapid7, attackers are using fake software installers for applications, such as LetsVPN and QQ Browser, to distribute the Winos 4.0 framework (also known as ValleyRAT malware).

Fake installers for LetsVPN & QQ Browser Winos 4.0 malware

The campaign relies heavily on a multi-stage loadercalled Catena. As security researchers Anna Širokova and Ivan Feigl point out, Catena incorporates shellcode and configuration switching logic to install payloads such as Winos 4.0 into memory, evading traditional antivirus tools.

Once executed, the malware silently connects to external C2 (Command-and-Control) servers, mainly located in Hong Kong, allowing attackers to monitor the system or install additional payloads at will.

The campaign's targets appear to be focused on Chinese-speaking users, with Rapid7 reporting that it is the work of a "capable and well-organized threat actor."

See also: Fake sites Zenmap and WinMTR distribute Bumblebee malware

Winos 4.0 (aka ValleyRAT malware), first documented by Trend Micro in June 2024, was also used in campaigns distributed via malicious MSI files masquerading as VPN applications. The activity was attributed to the Void Arachne (also known as Silver Fox).

In subsequent campaigns, threat actors had used gaming-related software, such as installation tools, speed boosters, and optimization utilities, as bait to attract new targets.

In a more recent wave of attacks, recorded in February 2025, attackers targeted public entities in Taiwan via phishing emails, which appeared to be official communications from the local tax agency.

Fake installers for LetsVPN & QQ Browser distribute Winos 4.0 malware

Winos 4.0: The new generation of Gh0st RAT with DDoS and detection evasion capabilities

Winos 4.0, an advanced malware written in C++, evolves on the basis of the well-known Gh0st RAT and brings a powerful “arsenal” for espionage, remote system control and DDoS attacks.

According to Rapid7, the malicious samples detected in February 2025 leveraged modified NSIS installers, which included signed decoy applications, malicious shellcode hidden in .ini , and reflective DLL injection, a technique that helps software remain on the system, avoiding detection.

See also: Operation Endgame 2.0: Authorities “hit” malware businesses

Researchers report that the campaign remains active throughout 2025, with some adjustments and improvements – characteristics that indicate the presence of an extremely capable and flexible threat actor.

The infection usually starts via a trojanized NSIS installer of QQ Browser, the popular Chromium-based browser developed by Tencent. From there, the Winos 4.0 malware installs itself on the system and communicates with C2 servers, using TCP ports 18856 and HTTPS 443 to transmit data and receive commands.

Persistence is achieved through registering scheduled tasks, which are activated weeks after the initial breach, making detection significantly more difficult. Although the malware checks whether the system is running in Chinese, it continues to run even if these settings are absent.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Rapid7 ’s latest analysis reveals that WinOS 4.0 attacks continue to evolve, with the company detecting a fake NSIS installer for LetsVPN in April . The program runs PowerShell commands to add Microsoft Defender exceptions for all available system drives – from **C:\ to Z:**. It then installs payloads that include an executable file that takes snapshots of active processes and checks for the presence of antivirus software , such as Qihoo 360 Total Security .

Notably, the executable is digitally signed with a (expired) VeriSign certificate , which is reportedly issued to Tencent Technology (Shenzhen) , valid from October 2018 to February 2020. The main function of the executable is to load a DLL file , which connects to remote C2 servers (such as 134.122.204[.]11:18852 and 103.46.185[.]44:443 ) to download and execute the Winos 4.0 malware.

See also: Authorities disrupted Lumma Stealer malware infrastructure

Fake installers for LetsVPN & QQ Browser distribute Winos 4.0 malware

Protection

  • Educating users about social engineering tactics and phishing attacks
  • Install (and update) antivirus and anti-malware software on all endpoints
  • Implement powerful email filters to block phishing emails and malicious attachments
  • Use of firewalls and intrusion detection/prevention systems (IDS/IPS)
  • Download software only from trusted sources
  • Network segmentation to limit the spread of malware
  • Implementation of the principle of least privilege (PoLP), so that users only have access to necessary resources
  • Multi-factor authentication (MFA) implementation
  • Updating operating systems, software and applications
  • Encryption of sensitive data
  • Continuous monitoring and analysis of system and network logs
  • Back  up important  data

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS