
WinosStager Loader Hides Behind Chrome, Routes All C2 Through Tor
A 66-megabyte Windows executable impersonating Google Chrome is circulating across ten countries with every command-and-control byte flowing through Tor hidden services, leaving no clearnet address for defenders to block or sinkhole. The binary, identified as WinosStager and linked to the CleverSoar campaign ecosystem, pairs startup-folder persistence with a suspected compile-on-host delivery chain targeting chemicals, consulting, government, and manufacturing sectors.
A 66,879-kilobyte Windows executable dressed as Google Chrome is circulating across chemicals, consulting, government, and manufacturing organisations in ten countries — and every byte of its command-and-control traffic flows exclusively through the Tor anonymity network to algorithmically generated .onion hidden services, leaving no clearnet address for network defenders to block, sinkhole, or pivot from.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read