A sophisticated phishing campaign has been identified targeting users across multiple Asian countries, including China, Taiwan, Japan, and Malaysia. The campaign initially surfaced in January 2025, when Fortinet researchers observed attacks in Taiwan utilizing the Winos 4.0 malware. By February, the threat actor had shifted tactics, deploying new malware families such as the HoldingHands Trojan and expanding operations to additional countries in the region. The attackers primarily targeted Microsoft Windows users, leveraging phishing emails that contained PDF attachments masquerading as official documents from ministries of finance and other government agencies. These malicious PDFs included multiple embedded links, most of which were hosted on Tencent Cloud storage. Unique account IDs embedded in the URLs allowed analysts to attribute various malicious files to the same threat actor, revealing a coordinated and expansive campaign. The phishing documents evolved over time, with some later versions imitating government purchase orders and tax regulation drafts to increase their credibility and lure victims. The campaign’s primary focus appeared to be Chinese-speaking individuals, as evidenced by the prevalence of Chinese-named malware variants found on VirusTotal. The attackers employed advanced obfuscation techniques to evade detection and maintain persistence within targeted environments. The stolen information from these attacks is believed to be used for future operations, indicating a likely motivation of regional intelligence collection. The malware deployed in these campaigns often remained dormant after infection, awaiting further commands from the attackers. Researchers highlighted the strategic connections between seemingly unrelated attacks by analyzing shared infrastructure, code patterns, and operational tactics. The use of Tencent Cloud for hosting malicious payloads provided the attackers with scalability and a degree of anonymity. The campaign’s expansion from China to Taiwan, then Japan, and most recently Malaysia, demonstrates the threat actor’s adaptability and intent to broaden their reach. Security analysts recommend heightened vigilance for phishing emails, especially those purporting to be from government agencies, and advise organizations to monitor for suspicious activity related to Tencent Cloud links. The campaign underscores the ongoing threat posed by well-resourced actors conducting cross-border cyber operations in Asia. Organizations are urged to update their threat models and incident response plans to account for these evolving tactics. The high severity of the campaign is attributed to its broad geographic scope, advanced techniques, and potential for significant intelligence compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On October 18, 2025, follow-on reporting associated the campaign with the Chinese threat group Silver Fox and emphasized its expansion from China and Taiwan into Japan and Malaysia using HoldingHands RAT and Winos 4.0-related tooling.
On October 17, 2025, FortiGuard Labs publicly tied the Taiwan, China, Japan, and Malaysia phishing clusters to a single actor using shared domains, IPs, scripts, debug paths, signed droppers, and Tencent Cloud account artifacts, and released associated indicators of compromise and detections.
Researchers identified an updated HoldingHands payload that can change its command-and-control server IP through a Windows registry value, allowing the operator to rotate infrastructure without redeploying the malware.
In the latest Malaysia-linked activity, the actor introduced a more evasive infection chain using DLL side-loading, Windows Task Scheduler restart behavior, in-memory decryption, anti-VM checks, and privilege-escalation techniques to reduce forensic visibility and evade defenses.
As the campaign expanded regionally, the actor began delivering the HoldingHands remote access trojan through phishing emails and cloud-hosted links, using shared infrastructure, Tencent Cloud-hosted content, and overlapping obfuscation methods to support intrusions across multiple countries.
By February 2025, the campaign had evolved from Winos 4.0 activity in Taiwan to broader operations across Asia, with the actor shifting to additional malware families and extending targeting into China, Japan, and Malaysia.
In early 2025, the threat actor launched phishing activity targeting Taiwan, using lures themed as government and business documents to deliver the Winos 4.0 malware family on Windows systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcefeeds.fortinet.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.