Winos 4.0 is a modular malware framework and intrusion ecosystem associated with Silver Fox activity and derived in part from the Gh0stRAT lineage. Reporting consistently describes it less as a single tightly bounded intrusion set than as a malware-as-a-service-style ecosystem with overlapping operators and tooling. The framework has been used in campaigns employing trojanized software lures, staged payload delivery, signed executable side-loading, in-memory decoding and manual mapping of follow-on modules, and multi-stage loaders that retrieve encrypted carrier files from cloud object storage. Observed Winos 4.0 tradecraft includes dynamic API resolution, anti-analysis timing and environment checks, tampering with telemetry-related functions, Windows Defender exclusion changes, elevated relaunch, scheduled-task persistence via Task Scheduler RPC, and use of multiple side-load clusters to decrypt and launch additional payloads. Later-stage components linked to this ecosystem have shown backdoor functionality, downloader logic, service-based persistence, cleanup routines, and checks for security products. Public analysis has also tied Winos 4.0 activity to Sauron backdoor behavior in some chains. The ecosystem has been reported expanding operations into Japan and Malaysia. Known associated names in public reporting include Winos, Winos 4.0, Silver Fox, and overlaps with Gh0stRAT-derived tooling. Because attribution boundaries are fuzzy, Winos 4.0 is best understood as a malware framework and operator ecosystem rather than a single clearly delineated threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular malware ecosystem/framework associated in the content with SilverFox campaigns, described as Gh0stRAT-derived and used to support staged loaders, side-loading chains, cloud-hosted payload delivery, and modular backdoor deployment.
Winos is expanding operations to Japan and Malaysia, deploying new malware as part of their campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.