Hackers Are Using Fake Apps Like LetsVPN and QQ Browser to Spread Stealthy Malware

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0. First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to […]

Cybersecurity researchers have uncovered a malware campaign using fake software installers to spread a powerful remote access tool. Masquerading as popular apps like LetsVPN and QQ Browser, the campaign is delivering a stealthy malware framework known as Winos 4.0.

First flagged by Rapid7 in February 2025, the operation relies on a loader called Catena to slip past antivirus defenses. The malware runs entirely in memory, making it harder to detect and remove.

Here’s how it works:

  • Trojan installers: Users download what looks like a legitimate app, like QQ Browser, but it’s a trojanized NSIS installer.
  • Memory-only payloads: Once executed, the Catena loader uses embedded shellcode to stage malware directly in memory.
  • C2 communication: The malware then connects to attacker-controlled servers—mostly in Hong Kong—over obscure TCP and HTTPS ports to receive commands or updates.

Researchers believe the campaign is targeting Chinese-speaking users, possibly as part of a broader surveillance or cyber-espionage effort.

Winos 4.0, also known as ValleyRAT, is based on the Gh0st RAT framework. Written in C++, it’s a plugin-powered tool that can:

  • Steal data
  • Open remote shell access
  • Launch DDoS attacks

Earlier versions of the malware were spread via phishing campaigns that impersonated Taiwanese tax authorities and gaming platforms.

In April 2025, the attackers adjusted their tactics. The new installers—posing as LetsVPN—run PowerShell commands to disable Microsoft Defender on all drives. They also deploy additional files that:

  • Take a snapshot of active processes
  • Look for Chinese antivirus software like 360 Total Security
  • Reflectively load DLLs to connect with command-and-control servers

One dropped executable was even signed with a certificate tied to Tencent, though it had expired. That trick is meant to make the malware seem more legitimate and avoid raising red flags.

Despite checking for Chinese language settings, the malware still runs even if the environment isn’t a match—possibly hinting at incomplete development.

Experts suspect this is the work of Silver Fox, a known advanced persistent threat (APT) group. The infrastructure, tactics, and regional focus all point to their involvement.

This campaign is another reminder: always verify the source before downloading software. Even apps that look familiar can be hiding dangerous payloads.

For corrections, news tips, and any other content requests, please send us an email at [email protected].

Hot this week

Here is What You Need to Know Why “Sidewalk Ban” Faces Backlash

The sidewalk ban ordinance in Albuquerque has raised concerns over people facing homelessness. Here is what you need to know.

Soaring Housing Costs Push Santa Fe Police Into Rio Rancho

Santa Fe police officers are increasingly living in Rio Rancho due to soaring housing costs, raising concerns about community connection and public safety.

Police: 4 Men Plotted Deadly Ambush Near UNM

A fatal shooting near the University of New Mexico campus is being investigated as a possible planned ambush after four suspects were taken into custody in the killing of 23-year-old Eden Rock. Police say surveillance footage showed the men hiding behind a dumpster before attacking and shooting the victim in an alley south of Central Avenue.

Sip, Savor, Celebrate, and More —Cocktail Week Takes Over New Mexico

New Mexico Cocktail Week returns for its fourth year, highlighting the state’s growing craft cocktail scene with events, tastings, and a shift toward mocktails.

APS Superintendent Honors Graduates: ‘Make the World a Better Place’

In her weekly message, Albuquerque Public Schools Superintendent Gabriella Durán Blakey recognized Class of 2026 graduates and thanked those behind their success.

Topics

Here is What You Need to Know Why “Sidewalk Ban” Faces Backlash

The sidewalk ban ordinance in Albuquerque has raised concerns over people facing homelessness. Here is what you need to know.

Soaring Housing Costs Push Santa Fe Police Into Rio Rancho

Santa Fe police officers are increasingly living in Rio Rancho due to soaring housing costs, raising concerns about community connection and public safety.

Police: 4 Men Plotted Deadly Ambush Near UNM

A fatal shooting near the University of New Mexico campus is being investigated as a possible planned ambush after four suspects were taken into custody in the killing of 23-year-old Eden Rock. Police say surveillance footage showed the men hiding behind a dumpster before attacking and shooting the victim in an alley south of Central Avenue.

Sip, Savor, Celebrate, and More —Cocktail Week Takes Over New Mexico

New Mexico Cocktail Week returns for its fourth year, highlighting the state’s growing craft cocktail scene with events, tastings, and a shift toward mocktails.

APS Superintendent Honors Graduates: ‘Make the World a Better Place’

In her weekly message, Albuquerque Public Schools Superintendent Gabriella Durán Blakey recognized Class of 2026 graduates and thanked those behind their success.

Las Cruces Catholic Diocese Pushes Back Against Border Wall Land Grab That Threatens Sacred Mount Cristo Rey

The U.S. government is seeking to seize land owned by the Roman Catholic Diocese of Las Cruces for border wall construction near Mount Cristo Rey, a revered pilgrimage site in southern New Mexico. The diocese argues the move violates religious freedom protections and threatens access to sacred ground visited by thousands each year.

Officials and U.S. Air Force Agree on PFAS Cleanup Plan at Cannon

In New Mexico, environmental officials have reached an agreement...

Agencies Focus on Outreach as Screwworm Threat Approaches

New Mexico agencies are focusing on outreach as the New World screwworm approaches, raising concerns among ranchers about livestock health and economic impacts. This headline matters because the screwworm, eradicated from the U.S. decades ago, has resurged in Mexico and threatens to cross the border.

Related Articles