newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Silver Fox Apt targets Taiwan with complex GH0stringe and HoldingHands rat malware
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Silver Fox Apt targets Taiwan with complex GH0stringe and HoldingHands rat malware
Technology

Silver Fox Apt targets Taiwan with complex GH0stringe and HoldingHands rat malware

June 17, 2025 3 Min Read
Share
Silver Fox Apt targets Taiwan with complex GH0stringe and HoldingHands rat malware
SHARE

Cybersecurity researchers are using malware families such as HoldingHands Rat and Gh0stringe to warn of new phishing campaigns targeting Taiwanese users.

The activity is part of a broader campaign that provided the Winos 4.0 malware framework in early January this year by sending phishing messages that impersonate Taiwan’s National Tax Agency, Fortinet Fortiguard Labs said in a report shared with Hacker News.

The cybersecurity company said it had identified additional malware samples through continuous monitoring and observed the same threat actors delivering GH0STCRINGE and malware stocks based on holding rats, using malware layer PDF documents or zip files distributed via phishing emails.

It is worth noting that both HoldingHands rats (aka GH0STBINS) and GH0STRinge are variations of known remote access trojans called GH0st rats, which are widely used in Chinese hacking groups.

Silver Fox Apt is targeting Taiwan

The starting point for the attack is a phishing email spoofing a message from a government or business partner, employing lures related to taxes, invoices and pensions to persuade recipients to open attachments. Alternate attack chains are known to utilize embedded images that download malware when clicked.

The PDF file contains a link that redirects future targets to the download page that hosts the ZIP archive. Within the file you will find some legitimate executables, shellcode loaders, and encrypted shellcode.

Multistage infection sequences require the use of a shellcode loader. This is nothing more than a DLL file sideloaded by a legitimate binary using DLL sideloading techniques. The intermediate payload deployed as part of the attack includes anti-VMs and privilege escalations to ensure that the malware is not being blocked by the compromised host.

This attack reaches its peak with the execution of “MSGDB.DAT”. This allows Command and Control (C2) to work to collect user information and download additional modules to facilitate file management and remote desktop functionality.

See also  New eddiestealer malware bypass Chrome's app-bind encryption and steal browser data

Fortinet also found threat actors propagating gh0stringe via PDF attachments in phishing emails that record users to download HTM pages.

“The attack chain consists of numerous snippets of shellcode and loader that complicates the flow of the attack,” the company said. “Beyond Winos, HoldingHands and Gh0stringe, this threat group is continuing to evolve its malware and distribution strategies.”

Share This Article
Facebook Twitter Copy Link
Previous Article Britain bets £250 M on the future of flight. Britain bets £250 M on the future of flight.
Next Article Trump denies Macron’s claim to enter into an early G7 summit exit and Israeli-Iran ceasefire contract Trump denies Macron’s claim to enter into an early G7 summit exit and Israeli-Iran ceasefire contract
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

How to speak ChatGpt normally
Technology

How to speak ChatGpt normally

18 Min Read
Anubis ransomware encrypts and wipes files, making recovery impossible even after payment
Technology

Anubis ransomware encrypts and wipes files, making recovery impossible even after payment

4 Min Read
How Manus AI is redefineing autonomous workflow automation across the industry
Technology

How Manus AI is redefineing autonomous workflow automation across the industry

11 Min Read
295 Malicious IPS launches a coordinated brute force attack against ApacheTomcat manager
Technology

295 Malicious IPS launches a coordinated brute force attack against ApacheTomcat manager

3 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?