RomulusLoader is a Windows malware loader associated with TA4922, a Chinese-speaking financially motivated threat actor with overlap to the broader Silver Fox ecosystem. First observed in 2026 campaigns targeting organizations in Japan and later Europe, it is used to stage and execute follow-on payloads and legitimate remote management software in support of remote access, fraud, data theft, and access resale operations. Delivery has been observed through localized business and human-resources-themed phishing lures, with execution commonly relying on DLL sideloading and archives hosted on consumer file-sharing services.
The malware is described as a C-based loader that downloads and executes additional payloads from command-and-control infrastructure. Reported execution methods include direct execution, shellcode injection, process hollowing, and process injection into legitimate Windows processes. RomulusLoader has also been used to deploy remote management tools such as AnyDesk and SyncFuture to blend malicious activity with normal administrative traffic. Some reporting further describes persistence-related behavior, including copying components into common system locations.
RomulusLoader forms part of a broader TA4922 toolset that also includes Atlas RAT, SilentRunLoader, and ValleyRAT/Winos4.0. Its role in campaigns is primarily as a staging utility rather than the final access payload, enabling operators to flexibly deliver additional malware or legitimate administration tools depending on the target and objective. Observed targeting has included Japanese organizations and later entities in Germany and other regions affected by TA4922 expansion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recent campaigns delivered a newly identified backdoor, Atlas RAT, alongside two fresh loader families Proofpoint named RomulusLoader and SilentRunLoader... TA4922 also blends in with legitimate software, using RomulusLoader to drop remote management tools (RMT) such as AnyDesk.
The disclosure comes as Silver Fox continues to actively refine and expand its arsenal with new tools, such as Atlas RAT (aka AtlasCross RAT), RomulusLoader, and SilentRunLoader...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent months, however, attacks mounted by the hacking group have relied on phishing campaigns using human resources- and business-themed lures for credential phishing, fraud, and malware delivery, including Atlas RAT, RomulusLoader, and SilentRunLoader.
To avoid detection, the loader masquerades as legitimate system components . For instance, analysts found variants mimicking the Vulkan Graphics API or AnyDesk software utilities .
It then injects its code into legitimate host processes like svchost.exe or dllhost.exe .
Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader mentioned as part of Silver Fox's expanding arsenal.
A loader malware family listed as part of Silver Fox's expanding arsenal.
A loader written in C that downloads and executes follow-on payloads from C2 servers, masquerades as legitimate components such as Vulkan Graphics API or AnyDesk utilities, side-loads a malicious library, maps malware into memory, persists in system directories, and injects into legitimate processes like svchost.exe or dllhost.exe.
A loader family introduced in TA4922 campaigns to stage additional tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.