logo

Chinese-Speaking Actor TA4922 Widens Its Global Reach

ID: 468f68cd-1967-5b24-b17e-5ab749e5cb64

STIX ID: report--468f68cd-1967-5b24-b17e-5ab749e5cb64

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

Proofpoint attributes a fast-evolving, financially motivated Chinese-speaking cybercrime group tracked as TA4922 with expanded targeting from Japan and East Asia into the UK, Germany, Italy and South Africa; the actor runs numerous campaigns using localized social engineering to deliver RATs and loaders (Atlas RAT, ValleyRAT/Winos 4.0, RomulusLoader, SilentRunLoader) via DLL sideloading and file-sharing, moves victims to messaging apps, deploys remote management tools like AnyDesk, and appears to use LLMs to accelerate Python malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.