logo

Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

ID: b935ad7d-ab7c-5e09-bdb5-750ce3961540

STIX ID: report--b935ad7d-ab7c-5e09-bdb5-750ce3961540

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Tushar Subhra Dutta

...
...

TA4922 is a financially motivated, globally active cybercrime group conducting targeted email-based campaigns that deliver multiple malware families (Atlas RAT, RomulusLoader, SilentRunLoader, ValleyRAT) to steal credentials, maintain persistent access, and enable fraud; the report documents campaign timelines, techniques (DLL sideloading, use of legitimate remote tools, anti-sandbox checks), provides IoCs (IPs, domains, URLs, SHA256 hashes, filenames), and recommends mitigations such as application allowlisting, monitoring execution from temporary folders, and least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.