Winos 4.0 Malware Uses Weaponized PDFs Posing as Government Departments to Infect Windows Machines
## Cybersecurity: High-Severity Malware Campaign Using Weaponized PDF Files
Cybersecurity: High-Severity Malware Campaign Using Weaponized PDF Files
Security researchers are monitoring a significant malware campaign that employs weaponized PDF files to distribute the Winos 4.0 malware.
The threat actors impersonate government departments to deceive users into opening malicious documents that compromise Microsoft Windows machines .
Initially detected in early 2025, the campaign has broadened its scope from Taiwan to Japan and Malaysia, adapting its tactics to circumvent detection.
Phishing Lures and Geographic Expansion
The attack initiates with a phishing email containing a PDF that appears to be an official document from a government agency, such as the Ministry of Finance.
These PDFs include malicious links that, when clicked, trigger the malware download. Initially, the payloads were hosted on Tencent Cloud storage, but later shifted to custom domains.
Researchers from FortiGuard Labs connected various attacks by analyzing unique IDs in the cloud storage URLs, identifying that the same threat actor was responsible for campaigns in different regions.
PDFs mimic government documents to gain credibility. Malicious links are often embedded resources, complicating detection. Researchers traced links and IDs to uncover the campaign infrastructure. Attackers adapt infrastructure and tactics for different regions and languages.
The threat actors have refined their methods to avoid security software and analysis. Recent attacks have transitioned from Winos 4.0 to a newer malware family called HoldingHands.
This malware is delivered through a complex, multi-stage infection process, utilizing legitimate-looking executables and DLL side-loading to bypass defenses. A notable change in the latest variant is the use of the Windows Task Scheduler to execute its components.
Security researchers are monitoring a significant malware campaign that employs weaponized PDF files to distribute the Winos 4.0 malware.
This mechanism allows the payload to run with elevated privileges while leaving fewer forensic artifacts, complicating detection through traditional monitoring.
HoldingHands replaces Winos 4.0 as the primary payload. Multi-stage execution involves DLL side-loading and indirect process triggering. Windows Task Scheduler complicates behavior-based detection. Malware checks for antivirus products and executes only if protections are absent.
The HoldingHands payload is designed for information theft, which can facilitate future attacks. It checks for antivirus products like Norton, Avast, and Kaspersky and will terminate itself if certain security processes are detected.
By linking shared infrastructure, code patterns, and operational tactics, researchers have identified a coordinated campaign spanning multiple countries.
The evolving malware and delivery mechanisms highlight a persistent threat to organizations across Asia, with stolen information posing significant risks for more targeted cyberattacks.
Domain IP SHA256
zxp0010w.vip 206.238.199.22 c138ff7d0b46a657c3a327f4eb266866957b4117c0507507ba81aaeb42cdefa9
gjqygs.cn 206.238.221.244 03e1cdca2a9e08efa8448e20b50dc63fdbea0e850de25c3a8e04b03e743b983d
zcqiyess.vip 206.238.199.22 2b1719108ec52e5dea20169a225b7d383ad450195a5e6274315c79874f448caa
jpjpz1.cc 154.91.64.45 dc45981ff705b641434ff959de5f8d4c12341eaeda42d278bd4e46628df94ac5
jppjp.vip 156.251.17.12 0db506d018413268e441a34e6e134c9f5a33ceea338fc323d231de966401bb2c
jpjpz1.top 206.238.221.182 031c916b599e17d8cfa13089bddafc2436be8522f0c9e479c7d76ba3010bbd18
(none) 38.60.203.110 c6095912671a201dad86d101e4fe619319cc22b10b4e8d74c3cd655b2175364c
Based on reporting by GBHackers.
