TA4922
TA4922 is a Chinese-speaking, likely East Asia-based threat actor tracked by Proofpoint since spring 2025 and assessed as primarily financially motivated. Proofpoint describes the group as a cybercrime operation rather than an espionage actor, although it notes overlap in tooling, infrastructure, and social engineering with Silver Fox and Void Arachne, and some malware capabilities could support surveillance. TA4922’s objectives are reported as obtaining remote access for monetization, including fraud, data theft, access brokering or resale, and persistence. TA4922 historically targeted organizations in East Asia, especially Japan, and has also targeted Taiwan, South Korea, Singapore, Malaysia, Indonesia, India, and Italy. By early 2026 it expanded targeting into Europe and Africa, including the United Kingdom, Germany, Italy, and South Africa. Proofpoint reported that the actor maintains a very high operational tempo and conducts more unique campaigns than any other cybercrime actor in its tracking. The actor relies heavily on localized phishing and impersonation. Observed lures include tax authority, payroll, HR, salary adjustment, benefits, compliance, invoice, and general business themes, often written in local languages and dialects. TA4922 also attempts to move victims from email to out-of-band platforms including LINE, WhatsApp, and Microsoft Teams to continue social engineering, harvest contact information, and deliver malware outside normal email security visibility. Proofpoint also observed tax-themed campaigns in which TA4922 impersonated national tax authorities, requested phone numbers, and then escalated contact by impersonating finance leadership. TA4922 uses diverse delivery and execution chains, including malicious links, archive attachments, cloud-hosted files, shortened URLs, direct executables, credential-phishing pages, DLL sideloading, and abuse of legitimate remote monitoring and management tools such as AnyDesk and SyncFuture. The group has used sender infrastructure at scale, including thousands of disposable sender addresses, often via Outlook, Hotmail, and Gmail accounts. Malware associated with TA4922 includes ValleyRAT/Winos4.0, Atlas RAT, RomulusLoader, and SilentRunLoader. ValleyRAT is described as part of the Winos4.0 ecosystem and provides full remote access functionality; Proofpoint also observed a heavily modified Winos4.0 variant in early 2026. Atlas RAT is a modular backdoor used against higher-value targets with capabilities including system reconnaissance, arbitrary command execution, file upload and management, plugin and payload loading, keylogging, screenshot capture, clipboard theft, audio recording, webcam capture, and system shutdown or reboot. Atlas RAT also performs anti-sandbox and anti-analysis checks. RomulusLoader is a C-based loader used to download and execute follow-on payloads and to deploy legitimate RMM software. Reported behaviors include masquerading as legitimate components such as Vulkan Graphics API or AnyDesk utilities, DLL sideloading, persistence via common system directories, shellcode execution, process injection into legitimate processes such as svchost.exe and dllhost.exe, process hollowing, and download-and-execute functionality. SilentRunLoader is a compiled Python-based loader and stealer focused on Google Chrome data theft. It harvests stored credentials, cookies, and browsing history, archives the data, and uploads it to actor-controlled infrastructure. Proofpoint assessed with high confidence that TA4922 likely uses large language models to accelerate development of some newer Python malware, citing placeholder values and coding artifacts in SilentRunLoader. Known aliases and related names mentioned in reporting include ValleyRAT/Winos4.0, Atlas RAT/AtlasCross RAT, and ecosystem overlap with Silver Fox and Void Arachne. Proofpoint tracks TA4922 as a distinct threat cluster.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Financial Services
Where they target
Geographies tied to known operations.
- 🇯🇵 Japan
- 🇹🇼 Taiwan
- 🇮🇳 India
- 🇬🇧 United Kingdom
- 🇩🇪 Germany
- 🇮🇹 Italy
- 🇿🇦 South Africa
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cybercrime group conducting high-volume malware campaigns using regionalized social engineering, out-of-band messaging shifts, and multiple loaders/backdoors against multinational corporations and government agencies.
Conducted campaigns using human resources and business-themed lures to deliver credential phishing, fraud, and newly identified malware, including Atlas RAT, with RomulusLoader and SilentRunLoader used to stage additional tools.
Financially motivated cybercrime actor conducting high-volume malware delivery campaigns for data theft, fraud, and persistent access. It uses localized HR-, tax-, and payroll-themed phishing lures, rapidly develops new Python-based malware, and has expanded operations from East Asia into Europe and South Africa.
China-linked, Chinese-speaking threat actor assessed as primarily financially motivated, conducting phishing campaigns to gain remote access for data theft, fraud, access resale, or persistent access. The group has expanded from largely targeting East Asia to also targeting European organizations and uses evolving malware delivery campaigns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.