Winos Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
December 11, 2025
Last Seen
June 17, 2026

Winos is a malware family noted for advanced, kernel-level capabilities.

Overview

Winos is a malware family noted for advanced, kernel-level capabilities. A recent report on ValleyRAT demonstrates the use of stealthy kernel-driver installation to bypass Windows 11 protections, illustrating the level of access and evasion that threats like Winos pursue. This technique enables persistence and deep system control, making it a significant concern for Windows endpoint defenses.

Related Threat Clusters

  • ValleyRAT Malware Targets Windows 11 with Advanced Stealth Techniques

    ValleyRAT, also known as Winos or Winos4.0, has emerged as a sophisticated backdoor targeting organizations globally. This malware specifically affects Windows systems, particularly those running Windows 11 with the…

    2 articles · Updated December 11, 2025
  • China Arrests 67 Members of Silver Fox Cybercrime Group

    Chinese authorities have arrested 67 suspects linked to the Silver Fox cybercrime group, which primarily targeted Chinese-speaking users. The arrests occurred across five provinces, including Zhejiang, Jilin, Shandong,…

    2 articles · Updated June 17, 2026

Recent Intelligence Reports

  • Check Point — research.checkpoint.com · June 17, 2026
  • Breakglass Intelligence — intel.breakglass.tech · June 17, 2026
  • Risky Bulletin: China arrests members of Silver Fox cybercrime group — News.Risky.Biz · June 17, 2026
  • ValleyRAT Malware Uses Stealthy Driver Install to Bypass Windows 11 Protections — Cybersecuritynews · December 11, 2025

CVSS v3.1 Breakdown