RomulusLoader is a Windows malware loader written in C and associated with TA4922, a Chinese-speaking, financially motivated threat cluster that overlaps in tooling and tradecraft with activity linked to Silver Fox. First observed in 2026, it is used to stage additional malware and legitimate remote management software during phishing-led intrusion campaigns targeting organizations in Japan, the United Kingdom, Germany, and other regions. Campaign lures have commonly impersonated human resources, business, tax, payroll, benefits, and compliance communications, with delivery observed through archive files and DLL sideloading chains.
RomulusLoader is designed to download and execute follow-on payloads from command-and-control infrastructure. Reported execution methods include direct execution, shellcode injection, process hollowing, and injection into legitimate Windows processes. It has also been observed masquerading as legitimate software components and abusing DLL sideloading to gain execution. Persistence has been reported through copying components into common system directories. In some campaigns, RomulusLoader was used to deploy legitimate remote monitoring and management tools such as AnyDesk and SyncFuture, helping operators blend malicious activity with normal administrative traffic and maintain access.
The malware forms part of a broader TA4922 toolkit that includes Atlas RAT, SilentRunLoader, and ValleyRAT/Winos4.0. Within that ecosystem, RomulusLoader serves as a staging utility rather than the primary surveillance or theft implant, enabling flexible post-compromise payload delivery and follow-on access. Its use alongside localized social engineering, disposable sender infrastructure, and out-of-band victim engagement reflects an intrusion model focused on scalable access operations, fraud, data theft, and persistent footholds in enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This new development indicates Silver Fox is actively refining its tradecraft, expanding its arsenal with malware families like Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader.
One standout tool in recent TA4922 malware campaigns is RomulusLoader, a unique utility written in C. This program downloads and executes subsequent payloads from command and control servers.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent months, however, attacks mounted by the hacking group have relied on phishing campaigns using human resources- and business-themed lures for credential phishing, fraud, and malware delivery, including Atlas RAT, RomulusLoader, and SilentRunLoader.
To avoid detection, the loader masquerades as legitimate system components . For instance, analysts found variants mimicking the Vulkan Graphics API or AnyDesk software utilities .
It then injects its code into legitimate host processes like svchost.exe or dllhost.exe .
Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.
This program downloads and executes subsequent payloads from command and control servers .
TA4922 might use a remote access Trojan (RAT), like ValleyRAT or Atlas RAT, to access targeted systems, or legitimate remote monitoring and management (RMM) software, like AnyDesk. In the latter case, it'll use a loader called RomulusLoader to bring the RMM onto the host system.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader malware family listed as part of Silver Fox's expanding arsenal.
A loader written in C that downloads and executes follow-on payloads from C2 servers, masquerades as legitimate components such as Vulkan Graphics API or AnyDesk utilities, side-loads a malicious library, maps malware into memory, persists in system directories, and injects into legitimate processes like svchost.exe or dllhost.exe.
A loader family introduced in TA4922 campaigns to stage additional tools.
RomulusLoader is a loader used to deliver additional payloads and legitimate remote monitoring tools, with execution commonly staged from temporary folders and C2 traffic observed on unusual ports including port 1234.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.