Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators TA4922: The Suspected Chinese Crime Group is Going Global

66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d

TLP:CLEAR
Active

SHA-256 Hash

Description

TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities. Initially targeting East Asia, particularly Japan, the group has expanded globally to Europe and Africa. The actor deploys multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), alongside legitimate remote management tools like AnyDesk and SyncFuture. Campaigns use localized lures themed around HR, payroll, tax, and invoicing, targeting hundreds to thousands of recipients per campaign. TA4922 conducts credential phishing, fraud operations including credit card theft, and attempts to shift communications to out-of-band channels like LINE, WhatsApp, and Microsoft Teams. The group leverages legitimate cloud hosting services and trusted software for delivery and persistence, combining advanced tradecraft with financially motivated objectives such as data theft, fraud, access resale, and persiste...

Sightings (0)

No sightings recorded yet

Details

Name / Label
TA4922: The Suspected Chinese Crime Group is Going Global
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 00:57
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.