Malware Disguised as VPN Poses New Threat to Users
A newly analyzed malware campaign is targeting users by disguising itself as a legitimate VPN service, notably LetsVPN. The malware, referred to as Winos 4.0, operates stealthily by bypassing Windows Defender and running directly from a device’s memory. Once active, it connects to attacker-controlled servers — mostly located in Hong Kong — enabling remote command execution, data theft, system shutdowns, and integration into botnets. The malicious software has primarily been distributed through fake installers of Google Chrome and LetsVPN, a VPN service based in China. While the current spread appears limited to Chinese-speaking regions, cybersecurity experts warn that its strategic deployment indicates a broader intent and potential expansion to other territories. Rapid7, the cybersecurity firm that studied the malware, underscores the risks of using lesser-known VPN providers, especially those operating under restrictive data privacy laws like those in China. The article advises users to stay safe by downloading software exclusively from official sources, maintaining up-to-date antivirus software, and opting for well-reviewed, globally trusted VPNs such as NordVPN. This incident serves as a reminder of the importance of digital hygiene and careful vetting of software sources.
