TA4922 is a Chinese-speaking, likely East Asia-based cybercrime threat actor first observed in 2025 and assessed to be primarily financially motivated. The group seeks remote access to victim environments for monetization through fraud, data theft, access brokering, and persistent footholds. Although its tooling and tradecraft overlap with activity associated with Silver Fox, Void Arachne, and the broader Winos4.0 ecosystem, TA4922 is generally tracked as a distinct cybercrime cluster rather than an espionage actor. TA4922 initially focused on organizations in Japan and other parts of East and Southeast Asia, including Taiwan, South Korea, Singapore, Malaysia, Indonesia, India, and surrounding regions. By 2026 it had expanded targeting into Europe and Africa, including the United Kingdom, Germany, Italy, and South Africa. Victimology spans both private- and public-sector organizations, with campaigns using highly localized lures tailored to regional language, business practices, and government processes. The actor is known for high campaign volume and rapid operational tempo. Its social engineering commonly uses tax, payroll, human resources, invoice, benefits, compliance, and broader business themes. TA4922 frequently impersonates tax authorities, finance departments, HR teams, executives, or colleagues. A notable pattern is the attempt to move conversations from email to out-of-band platforms such as WhatsApp, LINE, and Microsoft Teams, enabling extended social engineering, collection of contact information, and malware delivery outside normal email security visibility. TA4922 employs diverse initial access and delivery methods, including malicious links, archive attachments, credential-phishing pages, and multi-stage malware chains. DLL side-loading is a recurring execution technique across multiple campaigns. The actor also abuses legitimate remote monitoring and management software to blend into enterprise environments and maintain access. Its malware arsenal has expanded significantly and includes ValleyRAT, also known as Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, and AsyncRAT, as well as campaigns using the Cruciferra crypter service. ValleyRAT/Winos4.0 provides broad remote access functionality and has been a longstanding part of the actor’s ecosystem. Atlas RAT is a modular backdoor capable of system reconnaissance, command execution, file operations, keylogging, screenshot capture, clipboard theft, audio recording, webcam capture, and plugin or payload loading, with anti-analysis and sandbox-evasion features. RomulusLoader is a loader used to stage additional payloads and legitimate remote administration tools, supporting techniques such as shellcode execution, process injection, process hollowing, and persistence. SilentRunLoader is a Python-based loader and stealer focused on harvesting Google Chrome credentials, cookies, and browsing data before exfiltration. TA4922 has also used AnyDesk and SyncFuture as follow-on remote access tooling. Campaigns attributed to TA4922 have included tax-themed operations against targets in India that used Cruciferra to deliver AsyncRAT, as well as broader HR- and business-themed campaigns delivering Atlas RAT, RomulusLoader, and SilentRunLoader. The actor has also conducted credential-phishing and fraud-oriented operations in parallel with malware delivery, reflecting a flexible, opportunistic approach rather than reliance on a single intrusion pattern. Researchers have assessed with high confidence that some of TA4922’s newer Python-based malware may have been developed with assistance from large language models, based on coding artifacts and placeholder values. The group is notable for frequent tooling changes, modified malware variants, and rapid adaptation of delivery chains, all of which complicate classification and detection. Overall, TA4922 is a prolific and adaptive cybercrime actor distinguished by localized social engineering, broad geographic expansion, overlapping Chinese malware ecosystem ties, and a fast-evolving toolkit designed to obtain and monetize remote access at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
116 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-speaking cybercrime actor attributed with tax-themed phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams, using attacker-controlled landing pages hosting ZIP files to deliver malware and leveraging the Cruciferra crypter.
TA4922 is identified in the IoCs as the threat actor using the Cruciferra crypter in campaigns delivering AsyncRAT payloads via tax-themed lures and malicious downloads.
Chinese-speaking cybercrime actor observed using the Cruciferra crypter in multiple email campaigns with tax-themed lures and fake government tax portals to deliver AsyncRAT.
Financially motivated cybercrime group conducting high-volume malware campaigns using regionalized social engineering, out-of-band messaging shifts, and multiple loaders/backdoors against multinational corporations and government agencies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.