Skip to content

HoldingHands

HoldingHands is a Windows remote-access Trojan used in a cross-regional phishing campaign affecting targets in China, Taiwan, Japan, and Malaysia, with Chinese speakers identified as a primary focus.

Profile source: Mallory opens in a new tab

HoldingHands

Family profile

HoldingHands is a Windows remote-access Trojan used in a cross-regional phishing campaign affecting targets in China, Taiwan, Japan, and Malaysia, with Chinese speakers identified as a primary focus. It was deployed following earlier Winos 4.0 activity and has been linked to a threat cluster through shared infrastructure, obfuscation practices, and cloud-hosted lure content. Delivery commonly uses phishing emails and webpages masquerading as government finance correspondence, tax documents, purchase orders, and audit materials; victims are induced to download archives containing executables that initiate the infection chain. Later variants use a multi-stage execution flow involving DLL side-loading, encrypted staged components, Windows Task Scheduler recovery behavior, and execution through legitimate system processes to reduce forensic visibility and evade behavior-based defenses. The malware performs virtual-machine and security-product checks, alters execution in response to certain endpoint products, attempts elevation through TrustedInstaller thread impersonation, duplicates user tokens to execute in active user sessions, and injects the final payload into a trusted process with reinjection on termination. HoldingHands can also update its command-and-control server configuration remotely, facilitating infrastructure rotation without redeploying the malware.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Persistence
  • Privilege Escalation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 6, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • HK1

Leading providers

  • SonderCloud Limited1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TA4922

The actor has been historically associated with malware families including Winos4.0 (sometimes referred to as ValleyRAT) and HoldingHands.

MITRE ATT&CK

HoldingHands in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.