Winos, also referred to as WinOS and sometimes ValleyRAT in reporting on related campaigns, is a modular Windows remote-access trojan and backdoor framework used extensively in Chinese-speaking cybercrime and intrusion ecosystems. It has been associated with campaigns attributed to Silver Fox and other China-linked operators, and it has also appeared in activity tied to distributor-style malware delivery networks and gambling-focused threat clusters. The malware is commonly delivered through trojanized software installers, including MSI and EXE packages masquerading as popular consumer applications, translation tools, browsers, VPN software, office software, and fake Flash updates. Distribution has also been observed via SEO poisoning, counterfeit download portals, watering-hole style sites, and Telegram-based lure channels.
Winos is designed for full remote control of compromised Windows systems. Reported capabilities include command execution, remote shell access, file management, screenshot capture, webcam and microphone access, clipboard monitoring, keylogging, process and service management, plugin loading, and broader post-compromise surveillance and data theft. Some variants and plugin sets also support internal network scanning, privilege escalation, scheduled-task creation, startup persistence, process injection, and anti-analysis or anti-debugging checks. The framework has been described as plugin-based, with both internal and external modules enabling operators to extend functionality after initial compromise.
Observed infection chains typically use backdoored installers that deploy legitimate decoy software while silently launching staged malware components that establish persistence and ultimately load the Winos implant. Persistence mechanisms reported in Winos delivery chains include scheduled tasks, Windows services, Run-key style autoruns, and shortcut-based startup techniques. Operators have also used firewall-rule manipulation, port forwarding, and defense-evasion measures to maintain access and reduce detection.
Winos has been repeatedly used against Chinese-speaking users and has appeared in campaigns targeting sectors including gambling, technology, education, state-affiliated organizations, and other enterprises. Reporting indicates that leaked or reused code has contributed to broader adoption of the malware family beyond a single actor, making Winos a recurring component in multiple intrusion sets that rely on fake software distribution and social-engineering-heavy initial access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These MSI files act as backdoored installers, serving both the non-malicious software and the Winos 4.0 command-and-control (C&C) framework implant, which could lead to a full system compromise.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
所有搜索了特定仿冒软件的人都有可能下载到伪装的恶意安装包。 | 金眼狗团伙曾多次利用水坑网站托管恶意软件安装包,向受害者设备植入木马。金眼狗通过部署虚假的软件下载网站,再配合不同方式诱导受害者下载安装其恶意程序。
MITRE ATT&CK Mapping Tactic Technique ID Notes Initial Access Supply Chain Compromise T1195.002 Trojanized Chinese software distribution
After the second-stage loader (file “1”) is executed and loaded into memory, the malware drops a Visual Basic Script (VBScript) designed to automate the creation of a scheduled task within Windows Task Scheduler to achieve persistence.
The malware also uses the netsh command to set up port forwarding and configure firewall rules named “Safe<integer>” on the victim’s machine
the malware drops a Visual Basic Script (VBScript) designed to automate the creation of a scheduled task within Windows Task Scheduler
After decryption, the core function of the shellcode in Xps.dtd is to load the included PE and jump to the run export function to execute.
After the second-stage loader (file “1”) is executed and loaded into memory, the malware drops a Visual Basic Script (VBScript) designed to automate the creation of a scheduled task within Windows Task Scheduler to achieve persistence.
the stager then saves the decrypted C&C server response (the plugin and its configuration) into the Windows Registry. It uses the name "d33f351a4aeea5e608853d1a56661059" and stores it under the key path HKEY_CURRENT_USER\Console\0
After the second-stage loader (file “1”) is executed and loaded into memory, the malware drops a Visual Basic Script (VBScript) designed to automate the creation of a scheduled task within Windows Task Scheduler to achieve persistence.
Additionally, it supports many functionalities including process injection and microphone recording
Additionally, it supports many functionalities including process injection and microphone recording
The loader uses the Rivest Cipher 4 (RC4) algorithm with the key "0x678E0B00" to decrypt this data. After decryption, the payload, which is now executable code, is mapped into the process's memory space and executed.
If this feature is configured, the malware verifies the presence of monitoring software by inspecting the window titles of running processes. If such software is detected, the malware enters sleep mode.
During our investigation, we found the following external and custom plugins for Winos 4.0 in the wild: ... 内网主机扫描.dll Internal Network Host Scan.dll
The malware collects system information from an infected machine, including the IP address, computer name, antivirus software, operating system details, and hardware ID (HWID).
Winos has features that include file management, distributed denial of service (DDoS) using TCP/UDP/ ICMP/HTTP, full disk search
The stealer ran disguised as a WhatsApp backup application, using the User-Agent WhatsAppBackup/1.0 while communicating with a C2 server at xqwmwru[.]top.
The malware also uses the netsh command to set up port forwarding... Specifically, it designates port 443 as the listening port on the local machine
158 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows backdoor/C2 framework used by Chinese threat actors for full remote control of compromised systems. In this campaign it is delivered via malicious MSI installers and supports file management, DDoS, webcam and microphone access, screen capture, process injection, remote shell, keylogging, plugin loading, and registry-based storage of modules.
A remote access trojan, also referred to as ValleyRAT, used in related distributor activity tied to the broader Silver Fox ecosystem.
Malware family referenced in SEO poisoning/GitHub Pages distribution campaigns targeting Chinese-speaking users; no further details in excerpt.
Remote access trojan with a rich set of plug-ins for remote control and data theft, widely redeveloped by cybercrime and APT groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.