Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 6, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
HoldingHands is a Windows remote-access Trojan used in a cross-regional phishing campaign affecting targets in China, Taiwan, Japan, and Malaysia, with Chinese speakers identified as a primary focus.
Profile source: Mallory opens in a new tabHoldingHands
HoldingHands is a Windows remote-access Trojan used in a cross-regional phishing campaign affecting targets in China, Taiwan, Japan, and Malaysia, with Chinese speakers identified as a primary focus. It was deployed following earlier Winos 4.0 activity and has been linked to a threat cluster through shared infrastructure, obfuscation practices, and cloud-hosted lure content. Delivery commonly uses phishing emails and webpages masquerading as government finance correspondence, tax documents, purchase orders, and audit materials; victims are induced to download archives containing executables that initiate the infection chain. Later variants use a multi-stage execution flow involving DLL side-loading, encrypted staged components, Windows Task Scheduler recovery behavior, and execution through legitimate system processes to reduce forensic visibility and evade behavior-based defenses. The malware performs virtual-machine and security-product checks, alters execution in response to certain endpoint products, attempts elevation through TrustedInstaller thread impersonation, duplicates user tokens to execute in active user sessions, and injects the final payload into a trusted process with reinjection on termination. HoldingHands can also update its command-and-control server configuration remotely, facilitating infrastructure rotation without redeploying the malware.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
The actor has been historically associated with malware families including Winos4.0 (sometimes referred to as ValleyRAT) and HoldingHands.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.