Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 7 IP / 0 hostnames
Winos, also referred to as WinOS and sometimes ValleyRAT in reporting on related campaigns, is a modular Windows remote-access trojan and backdoor framework used extensively in Chinese-speaking cybercrime and intrusion ecosystems.
Profile source: Mallory opens in a new tabWinos
Winos, also referred to as WinOS and sometimes ValleyRAT in reporting on related campaigns, is a modular Windows remote-access trojan and backdoor framework used extensively in Chinese-speaking cybercrime and intrusion ecosystems. It has been associated with campaigns attributed to Silver Fox and other China-linked operators, and it has also appeared in activity tied to distributor-style malware delivery networks and gambling-focused threat clusters. The malware is commonly delivered through trojanized software installers, including MSI and EXE packages masquerading as popular consumer applications, translation tools, browsers, VPN software, office software, and fake Flash updates. Distribution has also been observed via SEO poisoning, counterfeit download portals, watering-hole style sites, and Telegram-based lure channels.
Winos is designed for full remote control of compromised Windows systems. Reported capabilities include command execution, remote shell access, file management, screenshot capture, webcam and microphone access, clipboard monitoring, keylogging, process and service management, plugin loading, and broader post-compromise surveillance and data theft. Some variants and plugin sets also support internal network scanning, privilege escalation, scheduled-task creation, startup persistence, process injection, and anti-analysis or anti-debugging checks. The framework has been described as plugin-based, with both internal and external modules enabling operators to extend functionality after initial compromise.
Observed infection chains typically use backdoored installers that deploy legitimate decoy software while silently launching staged malware components that establish persistence and ultimately load the Winos implant. Persistence mechanisms reported in Winos delivery chains include scheduled tasks, Windows services, Run-key style autoruns, and shortcut-based startup techniques. Operators have also used firewall-rule manipulation, port forwarding, and defense-evasion measures to maintain access and reduce detection.
Winos has been repeatedly used against Chinese-speaking users and has appeared in campaigns targeting sectors including gambling, technology, education, state-affiliated organizations, and other enterprises. Reporting indicates that leaked or reused code has contributed to broader adoption of the malware family beyond a single actor, making Winos a recurring component in multiple intrusion sets that rely on fake software distribution and social-engineering-heavy initial access.
C2 tracking
Derp observations, rolling seven-day window
Samples
4ba01b04681a5273facdd8b17e7b7b2246ee0eab6168c932946e7e96b9099e2d 646644adb0021c660b1d4410bca0976ca01f29ed0f109807f13ee9620b8d7625 a2a4be3a4b8c9738d92ff0dfa13886e2a629f9f820e2169ed33c883dc548ce4b a590f6666ac554d593be1d84e3e6e5864ff6b6074a07c1b7c4b355b9b218370b da169efdf43f4f2e87937efaaaf328dd659e28740411d1904a5bd0908ea5e061 33633ef8abb63a5ed8bcd1cf78e90f80438bb0236afe59714bfff83d73410428 7bbe66a44f25e522ce137bb617b095ff748fe93c714dc951b4f39c07b5a828a4 e4b632dc3f68ddb263b6cf9f0be4fbbfb7d24d1be2b448ad5f3f5ae573fc743b 42420ed30965b2e8cd0abfe59103f9352cf9e8bb9a1c75d340bf13b2660abda5 45247f9f1df5e1e11d59f13c402b288fbfbe403c74bd75e6207bcc7b2dba0682 Reported operators
These MSI files act as backdoored installers, serving both the non-malicious software and the Winos 4.0 command-and-control (C&C) framework implant, which could lead to a full system compromise.
经分析为银狐家族木马,最终释放了 Winos 实现远程控制。
经分析为银狐家族木马,最终释放了 Winos 实现远程控制。
Both types ultimately release the Winos Trojan.
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.