HoldingHands is a Windows remote-access Trojan used in a cross-regional phishing campaign affecting targets in China, Taiwan, Japan, and Malaysia, with Chinese speakers identified as a primary focus. It was deployed following earlier Winos 4.0 activity and has been linked to a threat cluster through shared infrastructure, obfuscation practices, and cloud-hosted lure content. Delivery commonly uses phishing emails and webpages masquerading as government finance correspondence, tax documents, purchase orders, and audit materials; victims are induced to download archives containing executables that initiate the infection chain. Later variants use a multi-stage execution flow involving DLL side-loading, encrypted staged components, Windows Task Scheduler recovery behavior, and execution through legitimate system processes to reduce forensic visibility and evade behavior-based defenses. The malware performs virtual-machine and security-product checks, alters execution in response to certain endpoint products, attempts elevation through TrustedInstaller thread impersonation, duplicates user tokens to execute in active user sessions, and injects the final payload into a trusted process with reinjection on termination. HoldingHands can also update its command-and-control server configuration remotely, facilitating infrastructure rotation without redeploying the malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actor has been historically associated with malware families including Winos4.0 (sometimes referred to as ValleyRAT) and HoldingHands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
“…the download link is fetched from the JSON data, rather than being stored in the script on the page.”
“…a social engineering lure that masquerades as a tax audit document to convince victims to run it.”
“msvchost.dat Encrypted shellcode… system.dat Encrypted payload… The process name also works as the decryption key…”
“…injecting malicious code into trusted processes like taskhostw.exe …”
“It then duplicates a logged-on user’s access token, allowing the shellcode to impersonate the user’s security context.”
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
HoldingHands is listed in the reference's tags and Malware Families list.
Mentioned as a malware family historically associated with TA4922, but the report provides no technical detail in this content.
Named malware referenced in the title; described only as malware involved in a task scheduler hijack technique to evade detection.
Multi-stage Windows backdoor/RAT delivered via phishing lures (PDF/Word/HTML) leading to ZIP/EXE droppers and DLL/shellcode stages; uses anti-analysis (anti-VM), privilege escalation via TrustedInstaller thread impersonation, AV process checks, Task Scheduler-based execution, and injects the final payload into user-context processes (e.g., taskhostw.exe). Includes a C2 task to update C2 IP via registry (HKCU\\SOFTWARE\\HHClient).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.