Researchers studying cybersecurity have revealed a malware campaign that distributes the Winos 4.0 framework by using phony software installers that pose as well-known programs like LetsVPN and QQ Browser.
The campaign uses a multi-stage, memory-resident loader dubbed Catena, which Rapid7 discovered for the first time in February 2025.
Security researchers Anna Širokova and Ivan Feigl stated that Catena avoids typical antivirus software by staging payloads like Winos 4.0 completely in memory with the use of embedded shellcode and configuration switching logic. After installation, it silently communicates to servers under the control of the attacker, most of which are located in Hong Kong, in order to obtain more malware or follow-up instructions.
The cybersecurity firm highlights the “careful, long-term planning” by a very competent threat actor, pointing out that the attacks read more about Hackers Use Fake VPN and Browser NSIS Installers to Deliver Winos 4.0 Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
