216.73.216.36

New Winos 4.0 Malware Infects Gamers Through Malicious Game Optimization Apps

· Published 06/11/2024 16:21 · Modified 06/11/2024 17:34

Export JSON

Essential information

Published
06/11/2024 16:21
Modified
06/11/2024 17:34
Tags
2024-11-06 command and control cryptocurrency wallets gh0st rat multi-stage infection optimization apps winos 4.0
Related entities
2 observables, 1 intrusion sets (apt), 15 techniques (mitre), 4 malware, 3 others

Description

A command-and-control framework called is being distributed through gaming-related applications, targeting Chinese-speaking users. The malware, rebuilt from , uses a process involving fake BMP files, DLLs, and shellcode. It can harvest system information, capture clipboard content, gather cryptocurrency wallet data, and enable backdoor functionality. also allows for additional plugins to capture screenshots and upload sensitive documents. The framework is considered powerful, similar to Cobalt Strike and Sliver, and exploits users' trust in game optimization tools to deploy deep system control.

External references