PULSE NAME
Winos4.0 malware disguised as KakaoTalk installation file
WHITE PetrP.73 2026-03-18 Modified: 2026-04-17
13
IOCs
MEDIUM VOLUME
The Winos4.0 malware is currently being disseminated through a search engine optimization (SEO) poisoning technique, where malicious sites are manipulated to rank highly in search results for credible software, specifically masquerading as an installation file for KakaoTalk. Recent reports confirm that over 5,000 devices have been infected by this malware, which initially appeared on March 9th. The malware pretends to be a KakaoTalk installer while secretly executing harmful activities upon installation.
Indicators of Compromise (5 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0ab84f52d043f7a7af54bd4df0331d64 2026-03-18
FileHash-MD5 108849450dd8410bf6217c9a7af82ab3 2026-03-18
FileHash-MD5 29152e0473edef5defc6752dabd0c53d 2026-03-18
FileHash-MD5 56ad524a33e5bb1ae8fee88d41b33294 2026-03-18
FileHash-MD5 8cad997c53fa31274ef0f542535c83b3 2026-03-18