China's TA4922 Expands Cybercrime Attacks Globally
ID: 2e093baf-8aa8-5400-b92e-cfa8300e0722
STIX ID: report--2e093baf-8aa8-5400-b92e-cfa8300e0722
Feed Name: Dark Reading
Proofpoint has observed TA4922 escalate from Japan-focused, tax-themed phishing to a broad, global phishing campaign targeting organizations across East Asia, Europe, and beyond; the group uses thousands of disposable sender addresses, social engineering in local languages, and diverse delivery chains including RATs (ValleyRAT, Atlas RAT), legitimate RMM abuse via loaders (RomulusLoader), DLL sideloading, credential phishing pages, and a Chrome stealer (SilentRunLoader), with overlaps to the Silver Fox cluster complicating attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
