NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign


The campaign was first spotted during a February 2025 MDR investigation. Since then, Rapid7 researchers have seen more samples using the same infection method—a multi-layered setup we call the Catena loader.

Catena uses embedded shellcode and configuration switching logic to stage payloads like Winos v4.0 entirely in memory, evading traditional antivirus tools. Once installed, it quietly connects to attacker-controlled servers—mostly hosted in Hong Kong—to receive follow-up instructions or additional malware. While the researchers have seen no signs of widespread targeting, the operation appears focused on Chinese-speaking environments and shows signs of careful, long-term planning by a capable threat group.

Read more…
Source: Rapid7


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • ShinyHunters and ReliaQuest trade blows over claimed breach

    August 24, 2026

    ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew’s social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim. The listing, seen by The Register, links to ...

  • Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring

    August 22, 2026

    Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains. WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. ...

  • Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants

    August 21, 2026

    Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems. The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants. The financial giant confirmed the incident in a letter filed with California’s ...

  • Securing the overlooked corners of the Software Development Lifecycle (SDLC) supply chain

    August 21, 2026

    While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at ...

  • Zombie Card: An expired Visa credit card can be used for purchases

    August 21, 2026

    Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, ...

  • The invisible passenger in your car

    August 21, 2026

    While monitoring Android threats in June 2026, Kaspersky discovered a new piece of Android malware. What struck the researchers as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might ...