logo

China's TA4922 Expands Cybercrime Attacks Globally

ID: 2e093baf-8aa8-5400-b92e-cfa8300e0722

STIX ID: report--2e093baf-8aa8-5400-b92e-cfa8300e0722

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-15

Author: Nate Nelson

...
...

Proofpoint has observed TA4922 escalate from Japan-focused, tax-themed phishing to a broad, global phishing campaign targeting organizations across East Asia, Europe, and beyond; the group uses thousands of disposable sender addresses, social engineering in local languages, and diverse delivery chains including RATs (ValleyRAT, Atlas RAT), legitimate RMM abuse via loaders (RomulusLoader), DLL sideloading, credential phishing pages, and a Chrome stealer (SilentRunLoader), with overlaps to the Silver Fox cluster complicating attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.