Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Winos 4.0 Malware Uses Weaponized PDFs Posing as Government Departments to Infect Windows Machines

## Cybersecurity: High-Severity Malware Campaign Using Weaponized PDF Files

Cybersecurity: High-Severity Malware Campaign Using Weaponized PDF Files

Security researchers are monitoring a significant malware campaign that employs weaponized PDF files to distribute the Winos 4.0 malware.

The threat actors impersonate government departments to deceive users into opening malicious documents that compromise Microsoft Windows machines .

Initially detected in early 2025, the campaign has broadened its scope from Taiwan to Japan and Malaysia, adapting its tactics to circumvent detection.

Phishing Lures and Geographic Expansion

The attack initiates with a phishing email containing a PDF that appears to be an official document from a government agency, such as the Ministry of Finance.

These PDFs include malicious links that, when clicked, trigger the malware download. Initially, the payloads were hosted on Tencent Cloud storage, but later shifted to custom domains.

Researchers from FortiGuard Labs connected various attacks by analyzing unique IDs in the cloud storage URLs, identifying that the same threat actor was responsible for campaigns in different regions.

PDFs mimic government documents to gain credibility. Malicious links are often embedded resources, complicating detection. Researchers traced links and IDs to uncover the campaign infrastructure. Attackers adapt infrastructure and tactics for different regions and languages.

The threat actors have refined their methods to avoid security software and analysis. Recent attacks have transitioned from Winos 4.0 to a newer malware family called HoldingHands.

This malware is delivered through a complex, multi-stage infection process, utilizing legitimate-looking executables and DLL side-loading to bypass defenses. A notable change in the latest variant is the use of the Windows Task Scheduler to execute its components.

Security researchers are monitoring a significant malware campaign that employs weaponized PDF files to distribute the Winos 4.0 malware.
Eleanor Tate · Thehackingpost

This mechanism allows the payload to run with elevated privileges while leaving fewer forensic artifacts, complicating detection through traditional monitoring.

HoldingHands replaces Winos 4.0 as the primary payload. Multi-stage execution involves DLL side-loading and indirect process triggering. Windows Task Scheduler complicates behavior-based detection. Malware checks for antivirus products and executes only if protections are absent.

The HoldingHands payload is designed for information theft, which can facilitate future attacks. It checks for antivirus products like Norton, Avast, and Kaspersky and will terminate itself if certain security processes are detected.

By linking shared infrastructure, code patterns, and operational tactics, researchers have identified a coordinated campaign spanning multiple countries.

The evolving malware and delivery mechanisms highlight a persistent threat to organizations across Asia, with stolen information posing significant risks for more targeted cyberattacks.

Domain IP SHA256

Advertisement

zxp0010w.vip 206.238.199.22 c138ff7d0b46a657c3a327f4eb266866957b4117c0507507ba81aaeb42cdefa9

gjqygs.cn 206.238.221.244 03e1cdca2a9e08efa8448e20b50dc63fdbea0e850de25c3a8e04b03e743b983d

zcqiyess.vip 206.238.199.22 2b1719108ec52e5dea20169a225b7d383ad450195a5e6274315c79874f448caa

jpjpz1.cc 154.91.64.45 dc45981ff705b641434ff959de5f8d4c12341eaeda42d278bd4e46628df94ac5

jppjp.vip 156.251.17.12 0db506d018413268e441a34e6e134c9f5a33ceea338fc323d231de966401bb2c

jpjpz1.top 206.238.221.182 031c916b599e17d8cfa13089bddafc2436be8522f0c9e479c7d76ba3010bbd18

(none) 38.60.203.110 c6095912671a201dad86d101e4fe619319cc22b10b4e8d74c3cd655b2175364c

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories