China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware
ID: f17cd821-850a-52f6-8517-9b822815880a
STIX ID: report--f17cd821-850a-52f6-8517-9b822815880a
Feed Name: HackRead
Proofpoint researchers track TA4922, a China-aligned financially motivated cybercrime group expanding from East Asia into the UK, Germany, Italy, and South Africa using bespoke tax/benefits/payroll-themed phishing lures to deliver a growing toolkit (ValleyRAT/Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader) that enables credential theft, remote access, fraud and persistent access via DLL sideloading and legitimate remote-management software; the report notes the likely use of LLMs in developing Python-based malware and highlights risks from targeted administrative-themed phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
