HoldingHands

First seen
2025-06-15 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:18:01

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:cn country_code:kr country_code:jp

Context

HoldingHands is a sophisticated modular Remote Access Trojan (RAT) and cyberespionage tool used primarily in targeted multi-stage campaigns across Asia. First documented in mid-2025, it operates as a variant of the Gh0st RAT family and is frequently deployed alongside other strains like Winos 4.0 and Gh0stCringe

Reports & references

  • proofpoint.com — Ta4922 Suspected Chinese Crime Group Going Global (report)

External references