logo

Chinese hackers use new Atlas RAT malware in European cyberattacks

ID: a665454d-7b4a-51c1-8262-a24d87d924d8

STIX ID: report--a665454d-7b4a-51c1-8262-a24d87d924d8

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Bill Toulas

...
...

**TA4922 expands into Europe with new malware and loaders** — Proofpoint documents a Chinese-speaking cybercrime group (TA4922) conducting high-tempo phishing campaigns across Germany, Italy, the UK and beyond, deploying Atlas RAT (remote access trojan), multiple loaders (RomulusLoader, SilentRunLoader) and ValleyRAT/Winos4.0 to perform reconnaissance, file theft, keylogging, audio/video capture and persistence, with anti-analysis features and evidence of active exploitation and diverse lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.