PULSE NAME
Winos4.0 malware disguised as KakaoTalk installation file
WHITE PetrP.73 2026-03-18 Modified: 2026-04-17
13
IOCs
MEDIUM VOLUME
The Winos4.0 malware is currently being disseminated through a search engine optimization (SEO) poisoning technique, where malicious sites are manipulated to rank highly in search results for credible software, specifically masquerading as an installation file for KakaoTalk. Recent reports confirm that over 5,000 devices have been infected by this malware, which initially appeared on March 9th. The malware pretends to be a KakaoTalk installer while secretly executing harmful activities upon installation.
Indicators of Compromise (2 / 13 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 be5a5e44ddcc8eb6d94fdb484246a4d3a6b41568bec7eb825ac633b9a27dcd44 SHA256 of 108849450dd8410bf6217c9a7af82ab3 2026-03-18
FileHash-SHA256 dffbf02773670e3dc6fad1e7fdbd746f43721bdedbfefc1d1f8a21e61ea23f95 SHA256 of 8cad997c53fa31274ef0f542535c83b3 2026-03-18