Fake VPN Installers Spread Winos 4.0
- Fake LetsVPN and QQ Browser installers deliver malware.
- Uses Catena loader to run payloads entirely in memory.
- Connects to attacker servers mainly hosted in Hong Kong.
- Targets Chinese-speaking users with long-term planning.
- Linked to threat group Void Arachne (Silver Fox).
