Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

SilentRunLoader

SilentRunLoader is a Python-based loader and information stealer used by the Chinese-speaking, financially motivated threat actor TA4922. Proofpoint first identified it on 30 March 2026 in campaigns targeting organizations in the United Kingdom, and later observed it in attacks against recipients in Southeast Asia and the U.K. The malware was delivered through localized phishing lures, particularly fake tax authority, benefits, and compliance-themed emails, including HMRC-themed messages, with delivery via links to MediaFire-hosted archives and through DLL sideloading. SilentRunLoader is described as both a loader and a Google Chrome stealer. It harvests sensitive data from Google Chrome, including stored credentials, cookies, and browsing information, and exfiltrates that data to actor-controlled infrastructure. Proofpoint reported exfiltration via HTTP POST to ws[.]ztts88[.]cyou, which resolved to 18[.]139[.]83[.]110, and also stated that the malware sent Chrome credentials to previously observed TA4922-controlled command-and-control infrastructure. The malware downloads or drops a next-stage executable named cg.exe. Proofpoint described it as a compiled Python sample whose internal name is "silent_run_and_upload.py". The report also noted an unchanged placeholder string, "your_secret_key_here," and assessed with high confidence that TA4922 likely used large language models to help develop some of its newer Python malware, including SilentRunLoader. SilentRunLoader is part of a broader TA4922 toolkit that also includes Atlas RAT, RomulusLoader, and ValleyRAT/Winos4.0, and has been used in campaigns against organizations in Europe and Asia.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA4922

But it also uses a loader called SilentRunLoader, and SilentRunLoader itself doubles as a Google Chrome stealer.

via dark readingdarkreading.com
MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1566PhishingEvidence3

In recent months, however, attacks mounted by the hacking group have relied on phishing campaigns using human resources- and business-themed lures for credential phishing, fraud, and malware delivery, including Atlas RAT, RomulusLoader, and SilentRunLoader.

T1566.001Spearphishing AttachmentEvidence2

The group sends carefully crafted emails disguised as messages from HR departments, tax authorities, and payroll teams... Once a victim clicks a link or opens an attachment, the malware silently installs itself.

T1566.002Spearphishing LinkEvidence3

Once a victim clicks a link or opens an attachment, the malware silently installs itself.

Execution

1 technique
T1059.006PythonEvidence2
TacticExecution

Proofpoint assessed with high confidence that the group likely uses AI coding tools to rapidly develop new Python-based malware.

Stealth

1 technique
T1218System Binary Proxy ExecutionEvidence1
TacticStealth

The target receives a legitimate executable file and a malicious DLL (the Atlas RAT loader) that is sideloaded into the executable’s process.

Credential Access

2 techniques
T1539Steal Web Session CookieEvidence4

SilentRunLoader itself doubles as a Google Chrome stealer.

T1555Credentials from Password StoresEvidence4

SilentRunLoader was deployed against UK targets using fake tax authority emails, stealing Chrome credentials and sending them to an actor-controlled server.

Discovery

1 technique
T1217Browser Information DiscoveryEvidence1
TacticDiscovery

Upon execution, the payload installed SilentRunLoader which harvested sensitive data from Google Chrome including stored credentials, cookies, and browsing information.

Collection

1 technique
T1560Archive Collected DataEvidence1

The downloaded executable (cg.exe) is another compiled Python executable and is responsible for gathering Chrome data and packing it into an archive, at which point the main Python code (SilentRunLoader) executes.

T1071Application Layer ProtocolEvidence1

Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.

T1105Ingress Tool TransferEvidence3

In the latter case, it'll use a loader called RomulusLoader to bring the RMM onto the host system. But it also uses a loader called SilentRunLoader

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence2

SilentRunLoader was deployed against UK targets using fake tax authority emails, stealing Chrome credentials and sending them to an actor-controlled server.

T1048.003Exfiltration Over Unencrypted Non-C2 ProtocolEvidence1

Collected data was exfiltrated via HTTP POST requests to C2 infrastructure hosted at “ws[.]ztts88[.]cyou” which resolved to IP address 18[.]139[.]83[.]110.

INDICATORS OF COMPROMISE

IOCs tracked for this family

7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
uri●●●●●●●●●●●●View more in apptoday
uri●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching7

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.