TA4922
TA4922 is a financially motivated, Chinese-speaking cybercrime threat actor tracked by Proofpoint since spring 2025. Proofpoint describes the group as China-linked or suspected China-aligned, likely based in East Asia, and distinct from espionage clusters despite overlaps in tooling, infrastructure, and social engineering with Silver Fox and Void Arachne. TA4922’s objective is to obtain remote access for monetization, including fraud, data theft, access brokering or resale, and persistence. The actor initially focused on Japan and other East Asian targets, including Taiwan, South Korea, Singapore, Malaysia, Indonesia, and India, and later expanded to the United Kingdom, Germany, Italy, and South Africa, with broader references to Europe and Southeast Asia. Proofpoint reported a sharp increase in TA4922 activity in March and April 2026 and assessed that it conducts more unique campaigns than any other cybercrime actor in its dataset. TA4922 relies heavily on localized social engineering. It uses phishing lures tailored to local languages and business processes, commonly themed around tax authorities, payroll, salary adjustments, HR notices, benefits, compliance, invoices, and business communications. The group commonly impersonates finance departments, HR teams, tax agencies, and victims’ colleagues, uses thousands of disposable sender accounts, and often attempts to move conversations from email to out-of-band channels including WhatsApp, Microsoft Teams, and LINE. Observed delivery and execution techniques include malicious links hosted on cloud or file-sharing services, archive attachments, direct executables, credential-phishing pages, DLL sideloading, and abuse of legitimate remote monitoring and management tools. TA4922 has used AnyDesk and SyncFuture after initial compromise. Its malware arsenal includes ValleyRAT (Winos4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. ValleyRAT/Winos4.0 provides full remote access capabilities, and Proofpoint observed newer variants in TA4922 activity. Atlas RAT is a modular backdoor with capabilities including system reconnaissance, file theft, plugin and payload download, keylogging, screenshot capture, audio and webcam recording, clipboard capture, remote command execution, and system shutdown or reboot; it also includes anti-analysis and anti-sandbox checks. RomulusLoader is a loader used to deploy additional payloads and legitimate RMM software, including AnyDesk and SyncFuture, and has been observed using DLL sideloading, process hollowing, shellcode injection, and download-and-execute functionality. SilentRunLoader is a Python-based loader and stealer that targets Google Chrome data, including stored credentials, cookies, and browsing information. Proofpoint also reported TA4922 activity in tax-themed campaigns, including impersonation of tax authorities and multi-stage social engineering designed to move victims out of email before delivering malware or remote access tooling. While Proofpoint assesses TA4922 as cybercrime-focused rather than espionage-focused, it noted that some of the malware used by the actor has surveillance-capable functionality and overlaps with the Silver Fox ecosystem. Known aliases and related names mentioned in the content include ValleyRAT/Winos4.0 for associated malware, Atlas RAT/AtlasCross RAT, and ecosystem overlap with Silver Fox and Void Arachne.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇯🇵 Japan
- 🇬🇧 United Kingdom
- 🇩🇪 Germany
- 🇿🇦 South Africa
Tradecraft
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cybercrime actor conducting high-volume malware delivery campaigns for data theft, fraud, and persistent access. It uses localized HR-, tax-, and payroll-themed phishing lures, rapidly develops new Python-based malware, and has expanded operations from East Asia into Europe and South Africa.
China-linked, Chinese-speaking threat actor assessed as primarily financially motivated, conducting phishing campaigns to gain remote access for data theft, fraud, access resale, or persistent access. The group has expanded from largely targeting East Asia to also targeting European organizations and uses evolving malware delivery campaigns.
A Chinese cybercrime cluster conducting broad global phishing and intrusion campaigns. It targets organizations across East Asia, Europe, and South Africa using localized finance- and business-themed lures, credential phishing, malware delivery, and remote access tooling.
Financially motivated cybercrime campaigns using phishing, credential theft, fraud attempts, remote access malware, loaders, browser-data theft, and legitimate remote management tools to maintain access.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.