logo

Proofpoint: TA4922 Deploys New RAT and Loader Arsenal

ID: eba09ef3-7350-53ec-a7e4-9b0041eaeaa4

STIX ID: report--eba09ef3-7350-53ec-a7e4-9b0041eaeaa4

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

TA4922 is a Chinese-speaking cybercriminal cluster tracked by Proofpoint that runs high-tempo, financially motivated campaigns using diverse malware (Atlas RAT, RomulusLoader, SilentRunLoader, ValleyRAT), DLL sideloading, and localized HR/tax-themed social engineering to gain persistent remote access, harvest credentials and browsing data, and exfiltrate information across targets in Japan, broader Asia, Europe, and Africa; the report includes detailed TTPs and many IOCs (IPs, URLs, file/ZIP/RAR and executable/DLL hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.