Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇨🇳 CN5 malware families

TA4922

Also known asta4922

TA4922 is a Chinese-speaking, likely East Asia-based threat actor tracked by Proofpoint since spring 2025 and assessed as primarily financially motivated. Proofpoint describes the group as a cybercrime operation rather than an espionage actor, although it notes overlap in tooling, infrastructure, and social engineering with Silver Fox and Void Arachne, and some malware capabilities could support surveillance. TA4922’s objectives are reported as obtaining remote access for monetization, including fraud, data theft, access brokering or resale, and persistence. TA4922 historically targeted organizations in East Asia, especially Japan, and has also targeted Taiwan, South Korea, Singapore, Malaysia, Indonesia, India, and Italy. By early 2026 it expanded targeting into Europe and Africa, including the United Kingdom, Germany, Italy, and South Africa. Proofpoint reported that the actor maintains a very high operational tempo and conducts more unique campaigns than any other cybercrime actor in its tracking. The actor relies heavily on localized phishing and impersonation. Observed lures include tax authority, payroll, HR, salary adjustment, benefits, compliance, invoice, and general business themes, often written in local languages and dialects. TA4922 also attempts to move victims from email to out-of-band platforms including LINE, WhatsApp, and Microsoft Teams to continue social engineering, harvest contact information, and deliver malware outside normal email security visibility. Proofpoint also observed tax-themed campaigns in which TA4922 impersonated national tax authorities, requested phone numbers, and then escalated contact by impersonating finance leadership. TA4922 uses diverse delivery and execution chains, including malicious links, archive attachments, cloud-hosted files, shortened URLs, direct executables, credential-phishing pages, DLL sideloading, and abuse of legitimate remote monitoring and management tools such as AnyDesk and SyncFuture. The group has used sender infrastructure at scale, including thousands of disposable sender addresses, often via Outlook, Hotmail, and Gmail accounts. Malware associated with TA4922 includes ValleyRAT/Winos4.0, Atlas RAT, RomulusLoader, and SilentRunLoader. ValleyRAT is described as part of the Winos4.0 ecosystem and provides full remote access functionality; Proofpoint also observed a heavily modified Winos4.0 variant in early 2026. Atlas RAT is a modular backdoor used against higher-value targets with capabilities including system reconnaissance, arbitrary command execution, file upload and management, plugin and payload loading, keylogging, screenshot capture, clipboard theft, audio recording, webcam capture, and system shutdown or reboot. Atlas RAT also performs anti-sandbox and anti-analysis checks. RomulusLoader is a C-based loader used to download and execute follow-on payloads and to deploy legitimate RMM software. Reported behaviors include masquerading as legitimate components such as Vulkan Graphics API or AnyDesk utilities, DLL sideloading, persistence via common system directories, shellcode execution, process injection into legitimate processes such as svchost.exe and dllhost.exe, process hollowing, and download-and-execute functionality. SilentRunLoader is a compiled Python-based loader and stealer focused on Google Chrome data theft. It harvests stored credentials, cookies, and browsing history, archives the data, and uploads it to actor-controlled infrastructure. Proofpoint assessed with high confidence that TA4922 likely uses large language models to accelerate development of some newer Python malware, citing placeholder values and coding artifacts in SilentRunLoader. Known aliases and related names mentioned in reporting include ValleyRAT/Winos4.0, Atlas RAT/AtlasCross RAT, and ecosystem overlap with Silver Fox and Void Arachne. Proofpoint tracks TA4922 as a distinct threat cluster.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Financial Services

Where they target

Geographies tied to known operations.

  • 🇯🇵 Japan
  • 🇹🇼 Taiwan
  • 🇮🇳 India
  • 🇬🇧 United Kingdom
  • 🇩🇪 Germany
  • 🇮🇹 Italy
  • 🇿🇦 South Africa

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics48 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598×2
Phishing for Information
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1133
External Remote Services
T1566×8
Phishing
T1566.001×4
Spearphishing Attachment
T1566.002×4
Spearphishing Link
T1566.003×2
Spearphishing via Service
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1059.003
Windows Command Shell
T1059.006×2
Python
T1106
Native API
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
2 techniques
T1055×3
Process Injection
T1055.012×3
Process Hollowing
T1078
Valid Accounts
TA0005
Stealth
5 techniques
T1036×4
Masquerading
T1055×3
Process Injection
T1055.012×3
Process Hollowing
T1078
Valid Accounts
T1218
System Binary Proxy Execution
T1497×3
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0006
Credential Access
3 techniques
T1056
Input Capture
T1056.001×4
Keylogging
T1539×5
Steal Web Session Cookie
T1555×5
Credentials from Password Stores
TA0007
Discovery
5 techniques
T1082×3
System Information Discovery
T1083×2
File and Directory Discovery
T1120
Peripheral Device Discovery
T1217
Browser Information Discovery
T1497×3
Virtualization/Sandbox Evasion
T1497.001
System Checks
TA0009
Collection
7 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001×4
Keylogging
T1113×3
Screen Capture
T1115×2
Clipboard Data
T1123×3
Audio Capture
T1125×4
Video Capture
T1560×2
Archive Collected Data
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×8
Ingress Tool Transfer
T1219×5
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1041×4
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
TA0040
Impact
1 technique
T1529
System Shutdown/Reboot
IOCS

Observables

27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
Jun 9, 2026
TA4922 Malware Campaigns: Proofpoint Cybercrime Analysis

Financially motivated cybercrime group conducting high-volume malware campaigns using regionalized social engineering, out-of-band messaging shifts, and multiple loaders/backdoors against multinational corporations and government agencies.

Read more
gurucul threat researchNews
Jun 5, 2026
TA4922: The Suspected Chinese Crime Group is Going Global | Community Portal | Gurucul

Conducted campaigns using human resources and business-themed lures to deliver credential phishing, fraud, and newly identified malware, including Atlas RAT, with RomulusLoader and SilentRunLoader used to stage additional tools.

Read more
cyber security newsNews
Jun 4, 2026
Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

Financially motivated cybercrime actor conducting high-volume malware delivery campaigns for data theft, fraud, and persistent access. It uses localized HR-, tax-, and payroll-themed phishing lures, rapidly develops new Python-based malware, and has expanded operations from East Asia into Europe and South Africa.

Read more
the hacker newsNews
Jun 4, 2026
China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

China-linked, Chinese-speaking threat actor assessed as primarily financially motivated, conducting phishing campaigns to gain remote access for data theft, fraud, access resale, or persistent access. The group has expanded from largely targeting East Asia to also targeting European organizations and uses evolving malware delivery campaigns.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping37

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables27

Domains, IPs, and hashes tied to this actor, refreshed continuously.