Hackers Are Using Fake Apps Like LetsVPN and QQ Browser to Spread Stealthy Malware

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0. First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to […]

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0.

First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to slip past antivirus defenses. The malware runs entirely in memory, making it harder to detect and remove.

Here’s how it works:

  • Trojan installers: Users download what looks like a legitimate app, like QQ Browser, but it’s a trojanized NSIS installer.
  • Memory-only payloads: Once executed, the Catena loader uses embedded shellcode to stage malware directly in memory.
  • C2 communication: The malware then connects to attacker-controlled servers—mostly in Hong Kong—over obscure TCP and HTTPS ports to receive commands or updates.

Researchers believe the campaign is targeting Chinese-speaking users, possibly as part of a broader surveillance or cyber-espionage effort.

Winos 4.0, also known as ValleyRAT, is based on the Gh0st RAT framework. Written in C++, it’s a plugin-powered tool that can:

  • Steal data
  • Open remote shell access
  • Launch DDoS attacks

Earlier versions of the malware were spread via phishing campaigns that impersonated Taiwanese tax authorities and gaming platforms.

In April 2025, the attackers adjusted their tactics. The new installers—posing as LetsVPN—run PowerShell commands to disable Microsoft Defender on all drives. They also deploy additional files that:

  • Take a snapshot of active processes
  • Look for Chinese antivirus software like 360 Total Security
  • Reflectively load DLLs to connect with command-and-control servers

One dropped executable was even signed with a certificate tied to Tencent, though it had expired. That trick is meant to make the malware seem more legitimate and avoid raising red flags.

Despite checking for Chinese language settings, the malware still runs even if the environment isn’t a match—possibly hinting at incomplete development.

Experts suspect this is the work of Silver Fox, a known advanced persistent threat (APT) group. The infrastructure, tactics, and regional focus all point to their involvement.

This campaign is another reminder: always verify the source before downloading software. Even apps that look familiar can be hiding dangerous payloads.

For corrections, news tips, and any other content requests, please send us an email at [email protected].

Hot this week

The Plague Didn’t Die Out in the 14th Century. It Just Claimed the Life of a Santa Fe Woman.

A Santa Fe County woman has died from plague, New Mexico's first human case of 2026. The tragedy is a sobering reminder that the disease that fueled the Black Death never disappeared. Though rare, plague still circulates among wildlife in the American West, making awareness, prevention and early treatment essential.

Ruidoso Downs Wildlife Fire Made Multiple Agencies To Respond; Residents Urged to Remain Alert

Ruidoso Downs wildfire has prompted The various emergencies to respond and urge residents to remain calm and vigilant in situations like this.

Parents Can Breathe a Massive Sigh of Relief. Free Child Care Is Officially Here to Stay After a District Judge Says So.

A New Mexico judge dismissed a lawsuit challenging the state's universal child care program, allowing free child care for families regardless of income to continue. The ruling marks a major victory for Governor Michelle Lujan Grisham and thousands of working parents who depend on the benefit, even as opponents vow to appeal.

New Wildfire on Mt. Taylor Ranger District

A forest fire broke out on June 8, 2026,...

Students Experiencing Homelessness Can Secure Free Documents Needed for Education – Here’s How

Homeless youth gain access to free state IDs and birth certificates under the state policy.

Topics

The Plague Didn’t Die Out in the 14th Century. It Just Claimed the Life of a Santa Fe Woman.

A Santa Fe County woman has died from plague, New Mexico's first human case of 2026. The tragedy is a sobering reminder that the disease that fueled the Black Death never disappeared. Though rare, plague still circulates among wildlife in the American West, making awareness, prevention and early treatment essential.

Ruidoso Downs Wildlife Fire Made Multiple Agencies To Respond; Residents Urged to Remain Alert

Ruidoso Downs wildfire has prompted The various emergencies to respond and urge residents to remain calm and vigilant in situations like this.

Parents Can Breathe a Massive Sigh of Relief. Free Child Care Is Officially Here to Stay After a District Judge Says So.

A New Mexico judge dismissed a lawsuit challenging the state's universal child care program, allowing free child care for families regardless of income to continue. The ruling marks a major victory for Governor Michelle Lujan Grisham and thousands of working parents who depend on the benefit, even as opponents vow to appeal.

New Wildfire on Mt. Taylor Ranger District

A forest fire broke out on June 8, 2026,...

Students Experiencing Homelessness Can Secure Free Documents Needed for Education – Here’s How

Homeless youth gain access to free state IDs and birth certificates under the state policy.

Heat Waves Continues; Flash Flood Risk Rises Near Ruidoso Burn Scars

Heat waves continue across the state, and the risk of flash flooding persists near Ruidoso Burn Scars.

Data Centers Are Coming to the Desert. The Price Tag? Millions of Gallons of Water.

The proposed mega data center in Socorro has ignited a fierce debate over water use, rural landscapes, and who really benefits from the AI boom as New Mexico courts tech infrastructure to move beyond oil and gas.

145 New Violations Issued: Who Made It to New Mexico’s Environmental ‘Enforcement Watch’ List?

State regulators added 145 alleged violations to New Mexico’s Enforcement Watch list in May while closing 93 cases. From a $34,000 refinery fire penalty to water system and emissions violations, here’s who made the list.

Related Articles