Fake VPN Installers Spread Winos 4.0
Fake VPN Installers Spread Winos 4.0
  1. Fake LetsVPN and QQ Browser installers deliver malware.
  2. Uses Catena loader to run payloads entirely in memory.
  3. Connects to attacker servers mainly hosted in Hong Kong.
  4. Targets Chinese-speaking users with long-term planning.
  5. Linked to threat group Void Arachne (Silver Fox).
#Winos4 #VoidArachne #FakeVPN #MemoryLoader #CyberAttack

Leave a Reply

Your email address will not be published. Required fields are marked *