Skip to main content
Mallory
🇨🇳 CN5 malware families

TA4922

Also known asta4922

TA4922 is a financially motivated, Chinese-speaking cybercrime threat actor tracked by Proofpoint since spring 2025. Proofpoint describes the group as China-linked or suspected China-aligned, likely based in East Asia, and distinct from espionage clusters despite overlaps in tooling, infrastructure, and social engineering with Silver Fox and Void Arachne. TA4922’s objective is to obtain remote access for monetization, including fraud, data theft, access brokering or resale, and persistence. The actor initially focused on Japan and other East Asian targets, including Taiwan, South Korea, Singapore, Malaysia, Indonesia, and India, and later expanded to the United Kingdom, Germany, Italy, and South Africa, with broader references to Europe and Southeast Asia. Proofpoint reported a sharp increase in TA4922 activity in March and April 2026 and assessed that it conducts more unique campaigns than any other cybercrime actor in its dataset. TA4922 relies heavily on localized social engineering. It uses phishing lures tailored to local languages and business processes, commonly themed around tax authorities, payroll, salary adjustments, HR notices, benefits, compliance, invoices, and business communications. The group commonly impersonates finance departments, HR teams, tax agencies, and victims’ colleagues, uses thousands of disposable sender accounts, and often attempts to move conversations from email to out-of-band channels including WhatsApp, Microsoft Teams, and LINE. Observed delivery and execution techniques include malicious links hosted on cloud or file-sharing services, archive attachments, direct executables, credential-phishing pages, DLL sideloading, and abuse of legitimate remote monitoring and management tools. TA4922 has used AnyDesk and SyncFuture after initial compromise. Its malware arsenal includes ValleyRAT (Winos4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. ValleyRAT/Winos4.0 provides full remote access capabilities, and Proofpoint observed newer variants in TA4922 activity. Atlas RAT is a modular backdoor with capabilities including system reconnaissance, file theft, plugin and payload download, keylogging, screenshot capture, audio and webcam recording, clipboard capture, remote command execution, and system shutdown or reboot; it also includes anti-analysis and anti-sandbox checks. RomulusLoader is a loader used to deploy additional payloads and legitimate RMM software, including AnyDesk and SyncFuture, and has been observed using DLL sideloading, process hollowing, shellcode injection, and download-and-execute functionality. SilentRunLoader is a Python-based loader and stealer that targets Google Chrome data, including stored credentials, cookies, and browsing information. Proofpoint also reported TA4922 activity in tax-themed campaigns, including impersonation of tax authorities and multi-stage social engineering designed to move victims out of email before delivering malware or remote access tooling. While Proofpoint assesses TA4922 as cybercrime-focused rather than espionage-focused, it noted that some of the malware used by the actor has surveillance-capable functionality and overlaps with the Silver Fox ecosystem. Known aliases and related names mentioned in the content include ValleyRAT/Winos4.0 for associated malware, Atlas RAT/AtlasCross RAT, and ecosystem overlap with Silver Fox and Void Arachne.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇬🇧 United Kingdom
  • 🇩🇪 Germany
  • 🇮🇹 Italy
  • 🇿🇦 South Africa
  • 🇯🇵 Japan

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics51 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598×2
Phishing for Information
TA0042
Resource Development
1 technique
T1586
Compromise Accounts
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1133
External Remote Services
T1566×7
Phishing
T1566.001×5
Spearphishing Attachment
T1566.002×5
Spearphishing Link
T1566.003
Spearphishing via Service
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.003
Windows Command Shell
T1059.006×2
Python
T1106
Native API
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
2 techniques
T1055×2
Process Injection
T1055.012×2
Process Hollowing
T1078
Valid Accounts
TA0005
Stealth
5 techniques
T1036×3
Masquerading
T1055×2
Process Injection
T1055.012×2
Process Hollowing
T1078
Valid Accounts
T1218
System Binary Proxy Execution
T1497×2
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0006
Credential Access
3 techniques
T1056
Input Capture
T1056.001×3
Keylogging
T1539×4
Steal Web Session Cookie
T1555×4
Credentials from Password Stores
TA0007
Discovery
5 techniques
T1082×2
System Information Discovery
T1083×2
File and Directory Discovery
T1120
Peripheral Device Discovery
T1217
Browser Information Discovery
T1497×2
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0009
Collection
7 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001×3
Keylogging
T1113×3
Screen Capture
T1115
Clipboard Data
T1123×2
Audio Capture
T1125×3
Video Capture
T1560
Archive Collected Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×7
Ingress Tool Transfer
T1219×6
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1041×4
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
TA0040
Impact
1 technique
T1529
System Shutdown/Reboot
IOCS

Observables

27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Jun 4, 2026
Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

Financially motivated cybercrime actor conducting high-volume malware delivery campaigns for data theft, fraud, and persistent access. It uses localized HR-, tax-, and payroll-themed phishing lures, rapidly develops new Python-based malware, and has expanded operations from East Asia into Europe and South Africa.

Read more
the hacker newsNews
Jun 4, 2026
China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

China-linked, Chinese-speaking threat actor assessed as primarily financially motivated, conducting phishing campaigns to gain remote access for data theft, fraud, access resale, or persistent access. The group has expanded from largely targeting East Asia to also targeting European organizations and uses evolving malware delivery campaigns.

Read more
dark readingNews
Jun 4, 2026
China's TA4922 Expands Cybercrime Attacks Globally

A Chinese cybercrime cluster conducting broad global phishing and intrusion campaigns. It targets organizations across East Asia, Europe, and South Africa using localized finance- and business-themed lures, credential phishing, malware delivery, and remote access tooling.

Read more
hackreadNews
Jun 3, 2026
China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware

Financially motivated cybercrime campaigns using phishing, credential theft, fraud attempts, remote access malware, loaders, browser-data theft, and legitimate remote management tools to maintain access.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping39

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables27

Domains, IPs, and hashes tied to this actor, refreshed continuously.