Skip to content

Winos

Winos, also referred to as WinOS and sometimes ValleyRAT in reporting on related campaigns, is a modular Windows remote-access trojan and backdoor framework used extensively in Chinese-speaking cybercrime and intrusion ecosystems.

Profile source: Mallory opens in a new tab

Winos

Family profile

Winos, also referred to as WinOS and sometimes ValleyRAT in reporting on related campaigns, is a modular Windows remote-access trojan and backdoor framework used extensively in Chinese-speaking cybercrime and intrusion ecosystems. It has been associated with campaigns attributed to Silver Fox and other China-linked operators, and it has also appeared in activity tied to distributor-style malware delivery networks and gambling-focused threat clusters. The malware is commonly delivered through trojanized software installers, including MSI and EXE packages masquerading as popular consumer applications, translation tools, browsers, VPN software, office software, and fake Flash updates. Distribution has also been observed via SEO poisoning, counterfeit download portals, watering-hole style sites, and Telegram-based lure channels.

Winos is designed for full remote control of compromised Windows systems. Reported capabilities include command execution, remote shell access, file management, screenshot capture, webcam and microphone access, clipboard monitoring, keylogging, process and service management, plugin loading, and broader post-compromise surveillance and data theft. Some variants and plugin sets also support internal network scanning, privilege escalation, scheduled-task creation, startup persistence, process injection, and anti-analysis or anti-debugging checks. The framework has been described as plugin-based, with both internal and external modules enabling operators to extend functionality after initial compromise.

Observed infection chains typically use backdoored installers that deploy legitimate decoy software while silently launching staged malware components that establish persistence and ultimately load the Winos implant. Persistence mechanisms reported in Winos delivery chains include scheduled tasks, Windows services, Run-key style autoruns, and shortcut-based startup techniques. Operators have also used firewall-rule manipulation, port forwarding, and defense-evasion measures to maintain access and reduce detection.

Winos has been repeatedly used against Chinese-speaking users and has appeared in campaigns targeting sectors including gambling, technology, education, state-affiliated organizations, and other enterprises. Reporting indicates that leaked or reused code has contributed to broader adoption of the malware family beyond a single actor, making Winos a recurring component in multiple intrusion sets that rely on fake software distribution and social-engineering-heavy initial access.

Capabilities

  • Ddos
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 8, 2026
Feed role
C2 / Distribution
Host form
7 IP / 0 hostnames

Leading locations

  • HK5
  • SG1
  • US1

Leading providers

  • CTG Server Limited2
  • Alibaba (US) Technology Co., Ltd.1
  • Cloudie Limited1
  • cognetcloud INC1
  • Turing Group Limited1
  • VoltNet inc1

Infrastructure traits

  • Hosting 7

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
Silver Fox

These MSI files act as backdoored installers, serving both the non-malicious software and the Winos 4.0 command-and-control (C&C) framework implant, which could lead to a full system compromise.

APT-Q-27

经分析为银狐家族木马,最终释放了 Winos 实现远程控制。

金眼狗

经分析为银狐家族木马,最终释放了 Winos 实现远程控制。

MITRE ATT&CK

Winos in ATT&CK

38 distinct techniques

Reporting

Research mentioning Winos

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.