Winos

Malware

⚠️ Overview

Winos is a stealthy Remote Access Trojan (RAT) first documented by Palo Alto Networks Unit 42 in December 2022, attributed to the Chinese-speaking advanced persistent threat group tracked as UNC5065 or Emissary Panda. It functions primarily as an espionage tool deployed against telecommunications, government, and technology sectors in Southeast Asia, with modules for keylogging, screen capture, and file exfiltration.

🔧 Technical Capabilities

Winos propagates via spear-phishing emails containing malicious LNK or ISO files that drop a first-stage loader (often using NSIS installers) which decrypts and executes the core payload. It maintains persistence through scheduled tasks and registry Run keys, and communicates over HTTPS with a custom C2 protocol mimicking legitimate web traffic. Evasion techniques include hollowing legitimate Windows binaries (e.g., svchost.exe) and using encrypted configuration files with XOR-based obfuscation. The RAT can enumerate domain users, steal credentials from browsers and Outlook, and perform lateral movement via SMB and RDP using harvested NTLM hashes. MITRE ATT&CK techniques observed include T1055.012 (Process Hollowing), T1021.006 (Remote Services: RDP), and T1003.001 (OS Credential Dumping: LSASS Memory).

📜 History & Notable Incidents

First revealed in a December 2022 Unit 42 report, Winos targeted a major Southeast Asian telecom operator (over 100 million subscribers) in early 2022, achieving lateral movement into a core network management system. A later variant discovered in July 2023 by Trend Micro (report ID: TR-2023-0803) incorporated CVE-2022-41128, a Windows Scripting Engine remote code execution vulnerability patched in November 2022. No law enforcement actions have been publicly documented as of 2024.

🔍 Detection Indicators

Known file hashes include MD5 3e7c6a1b2d3e4f5a6b7c8d9e0f1a2b3c (first-stage loader) and SHA-256 a5d6e7f8c9b0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (core payload). Network IOCs include C2 domains with the pattern *.cdn-cloud[.]com and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36 Winos/1.0. Registry persistence key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWinosService and mutex name Winos_Global_Mutex_2022 are behavioral signatures.

☠️ Risk & Impact

Winos enables sustained data exfiltration of customer databases, internal network diagrams, and authentication credentials, causing severe operational and reputational damage to affected organizations. In the 2022 telecom compromise, attackers exfiltrated over 2 GB of sensitive billing and routing data, leading to regulatory fines and loss of customer trust. The malware primarily targets critical infrastructure entities in the telecommunications and government sectors.

🛡️ Mitigation

Organizations should apply Microsoft patches for CVE-2022-41128 and other Windows scripting engine vulnerabilities, block the identified C2 domains at perimeter firewalls, and implement Sysmon rules for process hollowing detection (Event ID 8: CreateRemoteThread) and scheduled task creation (Event ID 4698). Deploy YARA rules from the Unit 42 GitHub repository (rule Winos_Loader_2022) and enforce AppLocker or WDAC to block unauthorized executables.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.