Hackers Are Using Fake Apps Like LetsVPN and QQ Browser to Spread Stealthy Malware

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0. First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to […]

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0.

First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to slip past antivirus defenses. The malware runs entirely in memory, making it harder to detect and remove.

Here’s how it works:

  • Trojan installers: Users download what looks like a legitimate app, like QQ Browser, but it’s a trojanized NSIS installer.
  • Memory-only payloads: Once executed, the Catena loader uses embedded shellcode to stage malware directly in memory.
  • C2 communication: The malware then connects to attacker-controlled servers—mostly in Hong Kong—over obscure TCP and HTTPS ports to receive commands or updates.

Researchers believe the campaign is targeting Chinese-speaking users, possibly as part of a broader surveillance or cyber-espionage effort.

Winos 4.0, also known as ValleyRAT, is based on the Gh0st RAT framework. Written in C++, it’s a plugin-powered tool that can:

  • Steal data
  • Open remote shell access
  • Launch DDoS attacks

Earlier versions of the malware were spread via phishing campaigns that impersonated Taiwanese tax authorities and gaming platforms.

In April 2025, the attackers adjusted their tactics. The new installers—posing as LetsVPN—run PowerShell commands to disable Microsoft Defender on all drives. They also deploy additional files that:

  • Take a snapshot of active processes
  • Look for Chinese antivirus software like 360 Total Security
  • Reflectively load DLLs to connect with command-and-control servers

One dropped executable was even signed with a certificate tied to Tencent, though it had expired. That trick is meant to make the malware seem more legitimate and avoid raising red flags.

Despite checking for Chinese language settings, the malware still runs even if the environment isn’t a match—possibly hinting at incomplete development.

Experts suspect this is the work of Silver Fox, a known advanced persistent threat (APT) group. The infrastructure, tactics, and regional focus all point to their involvement.

This campaign is another reminder: always verify the source before downloading software. Even apps that look familiar can be hiding dangerous payloads.

For corrections, news tips, and any other content requests, please send us an email at info@brant.one.

Hot this week

Nearly 3,000 Workers Train for Climate, Infrastructure Jobs as Clean Energy and Public Works Projects Ramp Up

The New Mexico Department of Workforce Solutions says 2,800 workers have completed training for climate-ready and infrastructure careers, surpassing earlier targets as the state prepares for a surge in clean energy and public works projects.

Job Right Out of High School? CEC Helps Make This Possible for Students

The Career Enrichment Center (CEC) helps prepare students for hands-on careers in their chosen fields.

Serving NMSU and the Community, Student Broadcasters Earn National Recognition

New Mexico University’s (NMSU) student broadcasters at KRUX 91.5 FM recently earned national recognition.

Jobless Claims Dipped —US Filings Edged Up to 212K

New Mexico records a slight dip in new unemployment claims even as nationwide filings inch up, signaling mixed labor market trends.

Seeking To Boost Your Spreadsheet Skills? This Training Series Has You Covered

New Mexico State University and NM EDGE collaborate to help individuals expand their spreadsheet skills through a practical training series.

Topics

Nearly 3,000 Workers Train for Climate, Infrastructure Jobs as Clean Energy and Public Works Projects Ramp Up

The New Mexico Department of Workforce Solutions says 2,800 workers have completed training for climate-ready and infrastructure careers, surpassing earlier targets as the state prepares for a surge in clean energy and public works projects.

Job Right Out of High School? CEC Helps Make This Possible for Students

The Career Enrichment Center (CEC) helps prepare students for hands-on careers in their chosen fields.

Serving NMSU and the Community, Student Broadcasters Earn National Recognition

New Mexico University’s (NMSU) student broadcasters at KRUX 91.5 FM recently earned national recognition.

Jobless Claims Dipped —US Filings Edged Up to 212K

New Mexico records a slight dip in new unemployment claims even as nationwide filings inch up, signaling mixed labor market trends.

Seeking To Boost Your Spreadsheet Skills? This Training Series Has You Covered

New Mexico State University and NM EDGE collaborate to help individuals expand their spreadsheet skills through a practical training series.

Celebrating Black History: UNM’s New AFRO Hair Shop Opens Its Doors

The AFRO Hair Shop recently opened at the University of New Mexico, offering a welcoming and inclusive environment for customers.

Residency Lawsuit Against Duke Rodriguez Dismissed. He’s Still in the NM Governor’s Race.

A Santa Fe judge threw out a lawsuit questioning Duke Rodriguez’s residency, the second court dismissal of challenges to his 2026 gubernatorial bid.

APS Reports Rising Graduation Rates for Class of 2025, Two Schools Exits MRI Status

Albuquerque Public Schools (APS) said that 12 of its 20 high schools increased graduation rates.

Related Articles