Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework


In early April, Trend Micro researchers discovered that a new threat actor group (which they call Void Arachne) was targeting Chinese-speaking users.

Void Arachne’s campaign involves the use of malicious MSI files that contain legitimate software installer files for artificial intelligence (AI) software as well as other popular software. The malicious Winos payloads are bundled alongside nudifiers and deepfake pornography-generating AI software, voice-and-face-swapping AI software, zh-CN (Simplified Chinese) language packs, the simplified Chinese version of Google Chrome, and Chinese-marketed virtual private networks (VPNs), such as LetsVPN and QuickVPN.

Read more…
Source: Trend Micro


Sign up for our Newsletter


Related:

  • A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies

    September 28, 2026

    A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more than $1 million from his victims. Cameron John Wagenius, 22, carried out the campaign while serving on active duty. He pleaded guilty in March 2025 to unlawfully transferring confidential phone records, ...

  • Recently disclosed Citrix vulnerabilities exploited in the wild

    September 28, 2026

    Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – ...

  • FBI agents’ blood tests and doctors’ notes surface after breach

    September 28, 2026

    BBC News reports it has seen samples of stolen FBI agents’ medical examinations. The “fitness-for-work” reports identify FBI agents by name and address, and reveal even more personal details. They include blood and urine test results and doctors’ notes mentioning high cholesterol, blood in the urine, and even a shellfish and banana allergy. As we reported ...

  • Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

    September 25, 2026

    Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them. Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first ...

  • Stolen passwords are exposing America’s water providers to hackers

    September 22, 2026

    New security research has found that well over a thousand U.S. water and wastewater providers are exposed to hacks due to malware that’s capable of stealing their employees’ passwords and active logged-in sessions. The findings by cybersecurity defense firm SpyCloud underscore how water providers and other critical infrastructure can be compromised with relative ease amidst a ...

  • ShinyHunters hackers say they breached FBI, stole data on bureau employees

    September 22, 2026

    The digital extortion group known as “ShinyHunters” said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a huge number of current and former FBI employees. The bureau did not respond to repeated messages seeking comment on Tuesday. In a statement posted to its dark-web site and during an online chat ...