PULSE NAME
Winos4.0 malware disguised as KakaoTalk installation file
WHITE PetrP.73 2026-03-18 Modified: 2026-04-17
13
IOCs
MEDIUM VOLUME
The Winos4.0 malware is currently being disseminated through a search engine optimization (SEO) poisoning technique, where malicious sites are manipulated to rank highly in search results for credible software, specifically masquerading as an installation file for KakaoTalk. Recent reports confirm that over 5,000 devices have been infected by this malware, which initially appeared on March 9th. The malware pretends to be a KakaoTalk installer while secretly executing harmful activities upon installation.
Indicators of Compromise (2 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 3249ec00233573f42a143bd1174b9fc410f200b7 SHA1 of 8cad997c53fa31274ef0f542535c83b3 2026-03-18
FileHash-SHA1 952ffa71595f56f58d0a392e0e86c6bf8c2a8aad SHA1 of 108849450dd8410bf6217c9a7af82ab3 2026-03-18