TA4922: The Suspected Chinese Crime Group is Going Global

TA4922: The Suspected Chinese Crime Group is Going Global
TA4922 is a highly active Chinese-speaking threat actor that has evolved its toolkit to include Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT/Winos4.0 while using regional HR, payroll, tax, and invoicing lures to target organizations across East Asia, Europe, and Africa. The group combines DLL sideloading, cloud hosting, trusted tools like AnyDesk and SyncFuture, and credential theft or exfiltration to support financially motivated access and fraud campaigns. #TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #Winos40 #AnyDesk #SyncFuture

Keypoints

  • TA4922 is assessed as a Chinese-speaking, likely East Asia-based threat actor with strong financial motives.
  • The group uses a rapidly changing malware arsenal, including Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT.
  • Campaigns rely on localized social engineering themes such as HR, payroll, tax audits, VAT filings, benefits, and invoicing.
  • Targeting initially focused on Japan and other parts of Asia, but expanded in 2026 to the U.K., Germany, Italy, South Africa, and other regions.
  • RomulusLoader is used as a first-stage loader to deploy additional payloads, including legitimate RMM tools like AnyDesk and SyncFuture.
  • SilentRunLoader steals Chrome data, including credentials and cookies, and exfiltrates it to actor-controlled infrastructure.
  • TA4922’s tradecraft includes DLL sideloading, process injection, anti-analysis checks, cloud/file-hosting abuse, and use of infrastructure tied to Chinese providers.

MITRE Techniques

  • [T1566.001] Phishing: Spearphishing Attachment – Used malicious archives and document-like lures to deliver payloads (‘the email contained a GoFile URL linking to a ZIP file’, ‘URLs in the email led to ZIP files hosted on GoFile’).
  • [T1566.002] Phishing: Spearphishing Link – Embedded URLs directed victims to hosted payloads and landing pages (‘URLs embedded in the email body redirected users to file sharing services’).
  • [T1204.001] User Execution: Malicious Link – Victims were induced to click links or open downloaded archives to launch the malware (‘designed to resemble internal HR notifications’, ‘urged recipients to review business documents’).
  • [T1574.002] Hijack Execution Flow: DLL Side-Loading – Multiple payloads were installed by abusing legitimate executables and DLLs (‘the Atlas RAT payload is installed via DLL sideloading’, ‘RomulusLoader was delivered inside a ZIP archive containing a legitimate executable and DLL’).
  • [T1105] Ingress Tool Transfer – Additional payloads were downloaded from actor infrastructure and file-sharing services (‘attempted to retrieve and execute additional payloads’, ‘download a next-stage payload’).
  • [T1055] Process Injection – RomulusLoader injected workers into other processes and Atlas RAT supported DLL injection into WeChat.exe (‘injected into other processes’, ‘injects DLL into WeChat.exe’).
  • [T1053.005] Scheduled Task/Job: Scheduled Task – Persistence was attempted through copying malware into a common program directory and reusing it via worker processes (‘copies the original executable … to the directory “C:Program FilesCommon Files” as a sort of persistence directory’).
  • [T1027] Obfuscated Files or Information – Payloads and configs were encrypted, compressed, or XOR-decoded (‘encrypted blob of data’, ‘decompresses it (ZLib)’, ‘hex-encoded’).
  • [T1140] Deobfuscate/Decode Files or Information – Malware decrypted embedded payloads and configuration data (‘decrypts the embedded PE file’, ‘The config is hex-encoded, and once decoded’).
  • [T1057] Process Discovery – Atlas RAT can check whether named processes are running (‘Process check (checks if named process is running)’).
  • [T1082] System Information Discovery – Atlas RAT collects and sends host information to C2 (‘gather system information and forward it to the C2’).
  • [T1113] Screen Capture – Atlas RAT can capture screenshots (‘Capture clipboard and screenshot data’).
  • [T1056.001] Input Capture: Keylogging – Atlas RAT includes keylogger functionality (‘Start a keylogger’).
  • [T1123] Audio Capture – Atlas RAT can record audio and access audio devices (‘Record audio and video (webcam)’, ‘checks for a camera as well as the audio … devices’).
  • [T1125] Video Capture – Atlas RAT supports webcam recording (‘Record audio and video (webcam)’).
  • [T1021.001] Remote Services: Remote Desktop Protocol – Legitimate remote management software was deployed to enable remote access, though via AnyDesk rather than RDP (‘deploy legitimate RMM software, AnyDesk’).
  • [T1090] Proxy – The actor used intermediaries such as file hosting, URL shorteners, and cloud services to reach victims and deliver payloads (‘srt.tw URLs … redirected to ZIP or RAR archive files hosted on MediaFire’).
  • [T1071.001] Application Layer Protocol: Web Protocols – C2 and exfiltration used HTTP/POST and web-hosted endpoints (‘exfiltrated via HTTP POST requests’).
  • [T1036] Masquerading – Malicious files and pages impersonated legitimate corporate, tax, and HR content (‘impersonating internal human resources communications’, ‘landing page impersonating a tax portal’).
  • [T1497.001] Virtualization/Sandbox Evasion: System Checks – Malware checked for sandbox, VM, and container indicators (‘Checks if the active username is “WDAGUtilityAccount”’, ‘Checks if the “CExecSvc” service is running’).
  • [T1059.006] Command and Scripting Interpreter: Python – SilentRunLoader is a Python-based loader/stealer (‘the Python-based loader and stealer tracked as SilentRunLoader’).

Indicators of Compromise

  • [IP address] C2 and exfiltration infrastructure – 206.238.115.58, 154.211.86.110
  • [IP address] RomulusLoader and SilentRunLoader infrastructure – 43.156.77.97, 18.139.83.110
  • [IP address] First-stage hosting / payload delivery – 103.214.172.33, 206.238.115.58
  • [Domain/URL] SilentRunLoader C2 and file hosting – ws.ztts88[.]cyou, https://ws.ztts88[.]cyou/file/cg[.]exe
  • [Domain/URL] SilentRunLoader exfiltration endpoint – https://ws.ztts88[.]cyou/upload[.]php, ws[.]ztts88[.]cyou
  • [Domain/URL] Campaign landing pages and hosted payloads – https://nwphotoblog[.]com, GoFile, MediaFire, LimeWire, srt.tw
  • [File hash] Atlas RAT archives and DLLs – a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295, 584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8
  • [File hash] RomulusLoader artifacts – 40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5, 8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0, 3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d
  • [File hash] RomulusLoader/SyncFuture artifacts – 314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279ef, 2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15d, 0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8
  • [File hash] SilentRunLoader executables and ZIP – e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088c, de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2, 9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73
  • [File name] Malicious archives and components – 【給与調整のお知らせ】.zip, Paperwork.zip, HR (2).zip, 会社文書.rar, vulkan-1.dll, vulkan-1.bin, libcef.dll, cg[.]exe


Read more: https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global