Proofpoint Warns TA4922 Deploys Atlas RAT and Multiple Malware Loaders
ID: 16d11fe6-a2b4-5209-8e26-4ca587c81a73
STIX ID: report--16d11fe6-a2b4-5209-8e26-4ca587c81a73
Feed Name: Cyber Press
TA4922 is a financially motivated, Chinese-speaking cybercriminal group conducting targeted social-engineering campaigns against organizations in Japan, Taiwan, Germany, and the UK. Their toolkit includes advanced loaders and backdoors (Atlas RAT, RomulusLoader, SilentRunLoader and modified Winos4.0/ValleyRAT variants), DLL sideloading, anti-sandbox and memory-resident shellcode techniques, and abuse of legitimate RMM tools; the report includes observed IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
