NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign
The campaign was first spotted during a February 2025 MDR investigation. Since then, Rapid7 researchers have seen more samples using the same infection method—a multi-layered setup we call the Catena loader. Catena uses embedded shellcode and configuration switching logic to Read More …

