Skip to content
Malware family Windows

Winos

WinOS, also known as ValleyRAT, is a Windows remote access trojan associated with the Silver Fox malware ecosystem and broader Chinese-language cybercrime activity.

Profile source: Mallory opens in a new tab

Winos

Family profile

WinOS, also known as ValleyRAT, is a Windows remote access trojan associated with the Silver Fox malware ecosystem and broader Chinese-language cybercrime activity. It has been distributed through counterfeit software installers and phishing-style download pages masquerading as popular applications and utilities, including fake Flash updates, translation tools, office software, browsers, and VPN software. Reported distribution methods include phishing websites, fake software download portals, SEO-driven lures, email, and instant messaging, with campaigns observed across Asia.

WinOS is a modular trojan designed for remote control and data theft on compromised hosts. Documented capabilities include plugin-based extensibility, screenshot capture, keylogging, clipboard theft, and broader remote-control functionality. Its modular architecture has enabled continued reuse and adaptation by multiple threat groups. In observed Windows infection chains, installer packages ultimately deploy the trojan after staging components that execute additional payloads and establish persistence through autorun mechanisms.

The malware has been described as one of the most common trojans used in Silver Fox operations. Reporting indicates that leaked source code contributed to wider redevelopment and reuse beyond a single operator, including adoption by cybercrime groups and some APT-linked actors. WinOS has therefore evolved from a family associated with one cluster into a more broadly reused malware platform within the Chinese threat landscape.

Capabilities

  • Credential Theft
  • Keylogging
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • HK1

Leading providers

  • VH Global Limited1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Silver Fox

These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.

MITRE ATT&CK

Winos in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.