RomulusLoader is a C-based Windows malware loader used by the Chinese-speaking, financially motivated threat actor TA4922. First identified in campaigns targeting Japanese organizations on March 23, 2026, it downloads and executes additional payloads from command-and-control servers. Subsequent campaigns targeted organizations in Japan and Germany and used the loader to deploy legitimate remote management software, including AnyDesk and SyncFuture, enabling attacker-controlled access while blending with legitimate software activity.
RomulusLoader is delivered through localized phishing campaigns using corporate, human resources, business, and tax-themed lures. Early campaigns distributed archives through the legitimate LimeWire file-sharing service. Its execution chain uses DLL sideloading through legitimate executables. Technical features include a custom Portable Executable loader, dynamic API resolution through PEB/TEB traversal and ROR13 hashing, and RC4-encrypted embedded payloads. It supports shellcode injection, process hollowing, and direct download-and-execute delivery, and injects worker code into legitimate Windows processes. Components are copied into shared system locations to support persistence.
TA4922 uses RomulusLoader within a broader operation focused on remote access, fraud, data theft, and access resale. The actor shares tooling, infrastructure, and social-engineering overlaps with the Silver Fox and Void Arachne ecosystems, but is tracked as a distinct cybercrime cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recent campaigns delivered a newly identified backdoor, Atlas RAT, alongside two fresh loader families Proofpoint named RomulusLoader and SilentRunLoader... TA4922 also blends in with legitimate software, using RomulusLoader to drop remote management tools (RMT) such as AnyDesk.
The disclosure comes as Silver Fox continues to actively refine and expand its arsenal with new tools, such as Atlas RAT (aka AtlasCross RAT), RomulusLoader, and SilentRunLoader...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent months, however, attacks mounted by the hacking group have relied on phishing campaigns using human resources- and business-themed lures for credential phishing, fraud, and malware delivery, including Atlas RAT, RomulusLoader, and SilentRunLoader.
To avoid detection, the loader masquerades as legitimate system components . For instance, analysts found variants mimicking the Vulkan Graphics API or AnyDesk software utilities .
It then injects its code into legitimate host processes like svchost.exe or dllhost.exe .
Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as the loader reached by a separate port 1234 package that shares the signed VulkanInfo host and DLL side-loading pattern. Its internals and the identity of its downstream RAT are not analyzed in this reference.
Mentioned as part of a separate port 1234 intrusion package sharing the signed VulkanInfo host and DLL side-loading pattern. That branch leads to a different, unnamed RAT and is not analyzed in this reference.
A loader mentioned as part of Silver Fox's expanding arsenal.
A loader malware family listed as part of Silver Fox's expanding arsenal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.