Multiple Malware Campaigns Abuse Phishing and Legitimate Cloud Services to Compromise Windows and Linux Systems
Reporting describes several unrelated but contemporaneous malware operations targeting both Windows and Linux environments. In Taiwan, FortiGuard Labs observed targeted phishing using tax and e-invoice lures to deliver Winos 4.0 (ValleyRat) and plugins, with delivery chains including malicious .LNK files, DLL sideloading, and BYOVD using the vulnerable driver wsftprm.sys, supported by rapidly rotating domains and cloud-hosted infrastructure that reduces the effectiveness of static blocklists. Separately, Cato CTRL reported a new Windows loader, Foxveil, that stages and retrieves shellcode via trusted platforms (Cloudflare Pages, Netlify, and Discord attachments) and executes payloads using techniques including Early Bird APC injection (often into a fake svchost.exe) or self-injection, while persisting via Windows services or masqueraded binaries dropped into SysWOW64.
Additional reporting covers distinct campaigns in other regions and platforms. A LATAM-focused intrusion chain uses fake bank receipt lures (double-extension such as .pdf.js) to deliver XWorm v5.6, employing oversized/obfuscated JavaScript, WMI-based process creation (Win32_Process) to launch hidden PowerShell, and abuse of a hardcoded Cloudinary URL for staging—capabilities consistent with credential theft and enabling follow-on ransomware. Trellix analysis described a separate Monero cryptomining operation distributed via pirated software installers that propagates through USB/external drives to reach even air-gapped systems, using multi-component “watchdog” self-healing behavior and aggressive defense-evasion. On Linux, LevelBlue detailed a new SysUpdate variant (packed ELF64) that performs host reconnaissance and uses strong C2 encryption; researchers built a Unicorn Engine-based emulation tool to reproduce key generation/encryption routines and decrypt captured C2 traffic for investigation and detection engineering.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
10 events from the most recent confirmed update back to the earliest known activity.
FortiGuard attributes Taiwan Winos activity to Silver Fox subgroup
FortiGuard attributed the Taiwan-focused Winos 4.0 campaigns with high confidence to a specialized subgroup within the Silver Fox APT. The attribution was based on overlapping infrastructure, identical driver-abuse techniques, domain registration artifacts, and a recurring development MachineID.
FortiGuard reports Winos 4.0 phishing campaigns targeting Taiwan
FortiGuard Labs disclosed targeted phishing campaigns in Taiwan using tax-themed lures to deliver Winos 4.0 (ValleyRat) and follow-on plugins. The campaigns use rotating domains, cloud-hosted archives, DLL sideloading, UAC bypass, and a vulnerable driver to disable security products and run memory-resident modules.
Researchers disclose advanced air-gap-bridging cryptomining malware
Trellix publicly described the cryptomining campaign's controller/payload separation, BYOVD privilege escalation, and CPU register tampering to improve Monero RandomX mining performance by an estimated 15–50%. The report also highlighted its ability to spread through removable media and bridge air-gapped systems.
XWorm campaign targets Latin American businesses with fake receipts
Researchers reported a multi-stage campaign targeting Brazilian and broader Latin American businesses with fake Bradesco bank receipt lures delivering XWorm v5.6. The infection chain uses a .pdf.js dropper, Cloudinary-hosted steganographic content, in-memory .NET loading, scheduled-task persistence, and CasPol.exe injection.
Researchers develop tool to decrypt SysUpdate Linux C2 traffic
To analyze the new SysUpdate variant, researchers built a Unicorn Engine-based emulation toolchain that reproduces the malware's key generation and decryption routines. The method enables defenders to decrypt intercepted C2 traffic from this and future variants by extracting updated keys from memory.
LevelBlue discovers new Linux SysUpdate variant
During a DFIR engagement, analysts found a suspicious packed ELF64 binary in a client environment and attributed it with high confidence to a new Linux-targeting SysUpdate variant. The malware masquerades as a system service, performs reconnaissance, and establishes encrypted multi-protocol C2 communications.
Researchers report Foxveil and its two variants
Security researchers publicly reported the newly discovered Foxveil loader and described two variants that differ in shellcode execution and injection methods. They also documented persistence via Windows services or lookalike executables in SysWOW64 and a runtime string-mutation feature to hinder analysis.
Cryptomining malware reaches built-in cleanup date
The cryptomining malware contains a hardcoded check for December 23, 2025, after which it switches to a cleanup mode that terminates components and deletes dropped files. This suggests the operators planned a defined campaign lifecycle.
Trellix identifies USB-spreading cryptomining campaign
Trellix said it identified a multi-stage cryptomining campaign in late 2025 that propagates through USB and external drives, including into air-gapped environments. The malware uses watchdog processes, kills security tools, and leverages the vulnerable WinRing0x64.sys driver for kernel access.
Foxveil malware loader activity begins
CATO CTRL assessed that the previously undocumented Foxveil malware loader has been active since August 2025. The loader abuses Cloudflare Pages, Netlify, and Discord attachments to stage shellcode and evade reputation-based defenses.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
5 references tracked. Mallory keeps watching after this page renders.
Massive Winos 4.0 Campaigns Target Taiwan | FortiGuard Labs
feeds.fortinet.com
Open sourceXWorm Delivered via Fake Financial Receipts Targeting Windows Systems
cybersecuritynews.com
Open sourceAdvanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems
cybersecuritynews.com
Open sourceNew SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic - Cyber Security News
cybersecuritynews.com
Open sourceNew 'Foxveil' Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection
cybersecuritynews.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


