TA4922 is a Chinese-speaking, likely East Asia-based cybercrime threat cluster first observed in 2025 and assessed to be primarily financially motivated. The actor seeks remote access to victim environments for monetization through fraud, data theft, access brokering, and persistent footholds. Although some tooling and tradecraft overlap with activity associated with Silver Fox and Void Arachne, TA4922 is generally tracked as a distinct cybercrime operation rather than an espionage actor. TA4922 initially focused on organizations in Japan and other parts of East Asia, including Taiwan, South Korea, Singapore, Malaysia, Indonesia, and India, before expanding in 2026 to targets in the United Kingdom, Germany, Italy, and South Africa. The group is notable for a very high campaign tempo and broad operational diversity, with reporting describing it as one of the most prolific cybercrime actors by number of unique campaigns. The actor relies heavily on localized social engineering. Its phishing lures commonly impersonate tax authorities, finance departments, human resources teams, payroll functions, compliance offices, benefits administrators, and sometimes real employees or executives. Themes include salary adjustments, invoices, tax filings, audits, payroll notices, benefits updates, and other business-process pretexts tailored to the victim’s language and region. TA4922 also frequently attempts to move conversations away from email and onto platforms such as LINE, WhatsApp, and Microsoft Teams, likely to evade enterprise email defenses, continue social engineering, harvest contact information, and deliver follow-on payloads outside normal monitoring channels. TA4922 uses a diverse malware arsenal that includes ValleyRAT, also known as Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, and in some campaigns commodity malware delivered through third-party malware-enablement services such as Cruciferra. ValleyRAT/Winos4.0 has been a recurring part of the actor’s ecosystem and provides broad remote access functionality. Atlas RAT is a modular backdoor used against higher-value targets and supports system reconnaissance, arbitrary command execution, file operations, plugin or payload loading, keylogging, screenshot capture, clipboard theft, audio recording, webcam capture, and system shutdown or reboot. Atlas RAT also incorporates anti-analysis and anti-sandbox checks. RomulusLoader is a loader associated with TA4922 that has been used to stage additional malware and legitimate remote management software. Reported capabilities include download-and-execute behavior, shellcode injection, process hollowing, custom PE loading, dynamic API resolution, persistence, and code injection into legitimate processes. TA4922 has used RomulusLoader to deploy remote monitoring and management tools such as AnyDesk and SyncFuture, blending malicious activity with legitimate administration software. SilentRunLoader is a compiled Python-based loader and stealer used by TA4922, particularly in tax- and compliance-themed campaigns. It is designed to harvest Google Chrome data, including stored credentials, cookies, and browsing history, package the stolen information, and exfiltrate it to attacker-controlled infrastructure. Assessments have linked some of TA4922’s newer Python malware development to likely use of large language models, based on placeholder values, comments, and coding artifacts consistent with AI-assisted generation. TA4922 commonly uses malicious links, archive attachments, disk image formats, executable-and-DLL pairings, and DLL sideloading to execute payloads. The actor also conducts credential phishing in some campaigns instead of malware delivery. Its tradecraft emphasizes flexibility and resilience, combining disposable sender infrastructure, cloud-hosted staging, legitimate tools, malware loaders, browser theft, and remote access tooling. While the group is assessed as cybercrime-focused, several of the malware families it uses have surveillance-capable features, creating the possibility that its tooling or access could also be leveraged by other actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
104 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-speaking cybercrime actor observed using the Cruciferra crypter in multiple email campaigns with tax-themed lures and fake government tax portals to deliver AsyncRAT.
Financially motivated cybercrime group conducting high-volume malware campaigns using regionalized social engineering, out-of-band messaging shifts, and multiple loaders/backdoors against multinational corporations and government agencies.
Conducted campaigns using human resources and business-themed lures to deliver credential phishing, fraud, and newly identified malware, including Atlas RAT, with RomulusLoader and SilentRunLoader used to stage additional tools.
Financially motivated cybercrime actor conducting high-volume malware delivery campaigns for data theft, fraud, and persistent access. It uses localized HR-, tax-, and payroll-themed phishing lures, rapidly develops new Python-based malware, and has expanded operations from East Asia into Europe and South Africa.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.