HoldingHands
- First seen
- 2025-06-15 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 13:18:01
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:cn country_code:kr country_code:jp
Context
HoldingHands is a sophisticated modular Remote Access Trojan (RAT) and cyberespionage tool used primarily in targeted multi-stage campaigns across Asia. First documented in mid-2025, it operates as a variant of the Gh0st RAT family and is frequently deployed alongside other strains like Winos 4.0 and Gh0stCringe
Reports & references
- proofpoint.com — Ta4922 Suspected Chinese Crime Group Going Global (report)