Rapid7 disclosed a targeted malware campaign using a new installer dubbed CleverSoar to infect Chinese- and Vietnamese-speaking Windows users with the Winos4.0 framework, the Nidhogg rootkit, and a custom backdoor. The installer performs extensive anti-analysis and targeting checks before execution, including VM and debugger detection, sandbox-user validation, and system language discovery consistent with MITRE ATT&CK T1614.001, then escalates privileges, disables security tools, turns off the Windows firewall, installs persistence, and hides artifacts. Rapid7 said the activity appears aligned with a long-running espionage effort focused on surveillance, keystroke logging, data theft, and covert remote control.
The findings overlap with Fortinet reporting on malware operations aimed at Chinese-speaking users, including a Winos4.0 campaign spread through trojanized gaming utilities and a separate ValleyRAT intrusion set attributed to the suspected Silver Fox group. Fortinet said Winos4.0 is a modular framework rebuilt from Gh0st RAT that uses staged loaders, shellcode injection, registry-stored modules, and persistence via Run keys or scheduled tasks, while plugins enabled screenshot capture, document theft, clipboard monitoring, and searches for crypto-wallet browser extensions. Rapid7 assessed with medium confidence that CleverSoar may be linked to the same actor behind Fortinet's ValleyRAT-related activity, citing shared tradecraft such as in-memory execution, anti-VM checks, privilege escalation, and evasion tailored to regional security products.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On November 6, 2024, FortiGuard Labs reported a malware campaign delivering the Winos4.0 framework through trojanized gaming-related applications such as installers, speed boosters, and optimization tools. The report detailed the staged infection chain, persistence methods, C2 communications, and surveillance and theft plugins.
Rapid7 Labs identified a new malware installer named CleverSoar in early November 2024. The installer targeted Chinese- and Vietnamese-speaking users and was used to deploy Winos4.0, the Nidhogg rootkit, and a custom backdoor.
On August 15, 2024, FortiGuard Labs published analysis of a multi-stage ValleyRAT campaign targeting Chinese-speaking Windows users. The report described in-memory shellcode execution, persistence, privilege-escalation, AV evasion, and attributed the activity to the suspected APT group Silver Fox.
Rapid7 reported that initial versions of the CleverSoar installer were uploaded to VirusTotal in late July 2024. This marks the earliest explicit anchor for the newly observed installer family later tied to Winos4.0 delivery.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
rapid7.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.