Massive Winos 4.0 Campaigns Target Taiwan
A series of targeted phishing campaigns in Taiwan have been observed disseminating Winos 4.0 (ValleyRat) malware and associated plugins. The attacks exploit local business processes using themes like tax audits and e-invoices. The campaigns employ various techniques including malicious LNK files, DLL sideloading, and Bring Your Own Vulnerable Driver (BYOVD) attacks. The malware utilizes UAC bypassing, driver loading, and process termination to evade detection and disable security software. The attacks are attributed to a subgroup of the Silver Fox APT, showing sophisticated localization and evolving evasion techniques. The campaigns have been active since at least January 2026, using consistent infrastructure and development identifiers.
Pulse ID: 699a6ee1425f8f4a6e583f31
Pulse Link: https://otx.alienvault.com/pulse/699a6ee1425f8f4a6e583f31
Pulse Author: AlienVault
Created: 2026-02-22 02:50:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #LNK #Malware #OTX #OpenThreatExchange #Phishing #RAT #SideLoading #bot #AlienVault
I forgot my last point.
4. The city planners of the last quarter century did not plan for a city of 150k people to grow to over 300k. (We get regular reminders of this.)
My normal drive to get home took over 75 minutes, about 45 minutes longer than usual. Downtown and Vine St were a mess. Holdrege wasn't much better.
Some people learned some things today.
1. Rear-wheel drive sports cars and vans should not be driving in this crap.
2. Good tires are important.
3. Regardless of the forecast, prepare for the worst.