TA4922 is a Chinese-speaking, China-linked financially motivated cybercrime group first observed in spring 2025. Its objectives include credential theft, fraud, data theft, and the resale of access to compromised systems. Initially concentrated on Japanese and other East Asian organizations, it expanded into Europe, South Asia, Southeast Asia, and South Africa. Its victims include small and medium-sized organizations. TA4922 shares overlaps in tooling, infrastructure, and social engineering with Silver Fox and Void Arachne, but is tracked as a distinct criminal activity cluster rather than an espionage operation; these overlapping clusters are not established aliases. The group conducts high-volume, localized phishing campaigns impersonating tax authorities, finance departments, human resources teams, and employees. Lures concern payroll, invoices, benefits, tax filings, and regulatory compliance. Initial email contact frequently transitions to LINE, WhatsApp, or Microsoft Teams, extending social engineering beyond enterprise email controls. Malware delivery uses attacker-controlled landing pages, consumer file-sharing services, archive attachments, disk images, and DLL sideloading through legitimate executables. TA4922's toolkit includes ValleyRAT/Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, AsyncRAT, and PackClient. RomulusLoader delivers additional payloads through process hollowing, injection, and direct execution, including legitimate remote-management tools such as AnyDesk and SyncFuture. SilentRunLoader steals Google Chrome credentials, session cookies, and browsing information and exfiltrates the collected data. Its RATs support reconnaissance, remote command execution, file theft, keylogging, and screen, audio, and webcam capture. PackClient adds modular plugins, proxy tunneling, persistence, and process-monitoring capabilities. Between late April and early June 2026, TA4922 used the Cruciferra crypter to deliver AsyncRAT through Indian tax-themed phishing. This delivery framework combines DLL sideloading with anti-analysis checks, security-monitoring evasion, vulnerable-driver abuse, privilege escalation, persistence, and modified process ghosting. Subsequent PackClient campaigns impersonated Chinese and Indian tax authorities, and July activity included deployment of ManageEngine remote-management software after compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in a cited report. The content does not explicitly attribute the Statement.exe and VulcanRAT207.A intrusion chain to TA4922.
Named only in a cited reference. The article does not explicitly attribute the Statement.exe and VulcanRAT207.A intrusion chain to TA4922 or establish its use of the described malware, vulnerabilities, or techniques.
Financially motivated group conducting tax-themed phishing campaigns to deliver the PackClient remote-access trojan. It historically targets small and medium-sized organizations in East Asia and has recently expanded targeting to Europe and the UK.
A Chinese-speaking threat actor expanding its initial-access arsenal with the PackClient modular C2 framework, which supports data theft, surveillance, and delivery of additional plugins and payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.