Winos
- First seen
- 2019-03-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-20 01:25:03
- Profile updated
- 2026-07-07 13:16:20
Targeted industries: financial-services technology-and-telecommunications
Context
Winos is a Remote Access Trojan (RAT) characterized by its ability to execute arbitrary commands on compromised systems. It is mainly used for cyber-espionage activities targeting financial and technology sectors.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Winos_Auto (yara-rule)
Reports & references
- Palo Alto Unit 42 — Espionage Campaign Targets South Asian Entities (report)
- cloudsek.com — Silver Fox Targeting India Using Tax Themed Phishing Lures (report)
- fortinet.com — Winos Spreads Via Impersonation Of Official Email To Target Users In Taiwan (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Winos (report)
- rapid7.com — Nsis Abuse And Srdi Shellcode Anatomy Of The Winos 4 0 Campaign (report)