TA4922 is a highly active Chinese-speaking threat actor that has evolved its toolkit to include Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT/Winos4.0 while using regional HR, payroll, tax, and invoicing lures to target organizations across East Asia, Europe, and Africa. The group combines DLL sideloading, cloud hosting, trusted tools like AnyDesk and SyncFuture, and credential theft or exfiltration to support financially motivated access and fraud campaigns. #TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #Winos40 #AnyDesk #SyncFuture
Keypoints
- TA4922 is assessed as a Chinese-speaking, likely East Asia-based threat actor with strong financial motives.
- The group uses a rapidly changing malware arsenal, including Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT.
- Campaigns rely on localized social engineering themes such as HR, payroll, tax audits, VAT filings, benefits, and invoicing.
- Targeting initially focused on Japan and other parts of Asia, but expanded in 2026 to the U.K., Germany, Italy, South Africa, and other regions.
- RomulusLoader is used as a first-stage loader to deploy additional payloads, including legitimate RMM tools like AnyDesk and SyncFuture.
- SilentRunLoader steals Chrome data, including credentials and cookies, and exfiltrates it to actor-controlled infrastructure.
- TA4922âs tradecraft includes DLL sideloading, process injection, anti-analysis checks, cloud/file-hosting abuse, and use of infrastructure tied to Chinese providers.
MITRE Techniques
- [T1566.001] Phishing: Spearphishing Attachment â Used malicious archives and document-like lures to deliver payloads (âthe email contained a GoFile URL linking to a ZIP fileâ, âURLs in the email led to ZIP files hosted on GoFileâ).
- [T1566.002] Phishing: Spearphishing Link â Embedded URLs directed victims to hosted payloads and landing pages (âURLs embedded in the email body redirected users to file sharing servicesâ).
- [T1204.001] User Execution: Malicious Link â Victims were induced to click links or open downloaded archives to launch the malware (âdesigned to resemble internal HR notificationsâ, âurged recipients to review business documentsâ).
- [T1574.002] Hijack Execution Flow: DLL Side-Loading â Multiple payloads were installed by abusing legitimate executables and DLLs (âthe Atlas RAT payload is installed via DLL sideloadingâ, âRomulusLoader was delivered inside a ZIP archive containing a legitimate executable and DLLâ).
- [T1105] Ingress Tool Transfer â Additional payloads were downloaded from actor infrastructure and file-sharing services (âattempted to retrieve and execute additional payloadsâ, âdownload a next-stage payloadâ).
- [T1055] Process Injection â RomulusLoader injected workers into other processes and Atlas RAT supported DLL injection into WeChat.exe (âinjected into other processesâ, âinjects DLL into WeChat.exeâ).
- [T1053.005] Scheduled Task/Job: Scheduled Task â Persistence was attempted through copying malware into a common program directory and reusing it via worker processes (âcopies the original executable ⌠to the directory âC:Program FilesCommon Filesâ as a sort of persistence directoryâ).
- [T1027] Obfuscated Files or Information â Payloads and configs were encrypted, compressed, or XOR-decoded (âencrypted blob of dataâ, âdecompresses it (ZLib)â, âhex-encodedâ).
- [T1140] Deobfuscate/Decode Files or Information â Malware decrypted embedded payloads and configuration data (âdecrypts the embedded PE fileâ, âThe config is hex-encoded, and once decodedâ).
- [T1057] Process Discovery â Atlas RAT can check whether named processes are running (âProcess check (checks if named process is running)â).
- [T1082] System Information Discovery â Atlas RAT collects and sends host information to C2 (âgather system information and forward it to the C2â).
- [T1113] Screen Capture â Atlas RAT can capture screenshots (âCapture clipboard and screenshot dataâ).
- [T1056.001] Input Capture: Keylogging â Atlas RAT includes keylogger functionality (âStart a keyloggerâ).
- [T1123] Audio Capture â Atlas RAT can record audio and access audio devices (âRecord audio and video (webcam)â, âchecks for a camera as well as the audio ⌠devicesâ).
- [T1125] Video Capture â Atlas RAT supports webcam recording (âRecord audio and video (webcam)â).
- [T1021.001] Remote Services: Remote Desktop Protocol â Legitimate remote management software was deployed to enable remote access, though via AnyDesk rather than RDP (âdeploy legitimate RMM software, AnyDeskâ).
- [T1090] Proxy â The actor used intermediaries such as file hosting, URL shorteners, and cloud services to reach victims and deliver payloads (âsrt.tw URLs ⌠redirected to ZIP or RAR archive files hosted on MediaFireâ).
- [T1071.001] Application Layer Protocol: Web Protocols â C2 and exfiltration used HTTP/POST and web-hosted endpoints (âexfiltrated via HTTP POST requestsâ).
- [T1036] Masquerading â Malicious files and pages impersonated legitimate corporate, tax, and HR content (âimpersonating internal human resources communicationsâ, âlanding page impersonating a tax portalâ).
- [T1497.001] Virtualization/Sandbox Evasion: System Checks â Malware checked for sandbox, VM, and container indicators (âChecks if the active username is âWDAGUtilityAccountââ, âChecks if the âCExecSvcâ service is runningâ).
- [T1059.006] Command and Scripting Interpreter: Python â SilentRunLoader is a Python-based loader/stealer (âthe Python-based loader and stealer tracked as SilentRunLoaderâ).
Indicators of Compromise
- [IP address] C2 and exfiltration infrastructure â 206.238.115.58, 154.211.86.110
- [IP address] RomulusLoader and SilentRunLoader infrastructure â 43.156.77.97, 18.139.83.110
- [IP address] First-stage hosting / payload delivery â 103.214.172.33, 206.238.115.58
- [Domain/URL] SilentRunLoader C2 and file hosting â ws.ztts88[.]cyou, https://ws.ztts88[.]cyou/file/cg[.]exe
- [Domain/URL] SilentRunLoader exfiltration endpoint â https://ws.ztts88[.]cyou/upload[.]php, ws[.]ztts88[.]cyou
- [Domain/URL] Campaign landing pages and hosted payloads â https://nwphotoblog[.]com, GoFile, MediaFire, LimeWire, srt.tw
- [File hash] Atlas RAT archives and DLLs â a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295, 584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8
- [File hash] RomulusLoader artifacts â 40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5, 8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0, 3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d
- [File hash] RomulusLoader/SyncFuture artifacts â 314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279ef, 2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15d, 0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8
- [File hash] SilentRunLoader executables and ZIP â e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088c, de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2, 9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73
- [File name] Malicious archives and components â ă羌ä¸čŞżć´ăŽăçĽăăă.zip, Paperwork.zip, HR (2).zip, äźç¤žćć¸.rar, vulkan-1.dll, vulkan-1.bin, libcef.dll, cg[.]exe
Read more: https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global