3w ago · fortinet
FortiGuard Labs has identified a persistent hacker group conducting phishing campaigns across Asia, targeting users in Mainland China, Taiwan, Japan, and Malaysia. The group uses malicious PDFs, Word, and Excel documents that mimic official government communications to deliver malware such as Winos 4.0 and HoldingHands. The attacks have evolved to include multi-stage delivery mechanisms, abuse of legitimate digital signatures, and use of Windows Task Scheduler for stealthy execution, complicating detection and analysis.