TA4922: The Suspected Chinese Crime Group is Going Global
TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities. Initially targeting East Asia, particularly Japan, the group has expanded globally to Europe and Africa. The actor deploys multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), alongside legitimate remote management tools like AnyDesk and SyncFuture. Campaigns use localized lures themed around HR, payroll, tax, and invoicing, targeting hundreds to thousands of recipients per campaign. TA4922 conducts credential phishing, fraud operations including credit card theft, and attempts to shift communications to out-of-band channels like LINE, WhatsApp, and Microsoft Teams. The group leverages legitimate cloud hosting services and trusted software for delivery and persistence, combining advanced tradecraft with financially motivated objectives such as data theft, fraud, access resale, and persistent remote access.
Pulse ID: 6a20244bdece9b50eee824aa
Pulse Link: https://otx.alienvault.com/pulse/6a20244bdece9b50eee824aa
Pulse Author: AlienVault
Created: 2026-06-03 12:55:39
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #AnyDesk #Asia #Chinese #Cloud #CreditCard #CyberSecurity #DataTheft #Europe #InfoSec #Japan #Malware #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #Phishing #RAT #Rust #WhatsApp #bot #AlienVault