Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ta4922

Also known as: tracked as, tax professionals, corporate finance teams, data theft, Italy, the United Kingdom, South Africa, Silver Fox, Void Arachne, ValleyRAT, control capabilities after compromise

Description

TA4922 is a sophisticated threat actor whose primary motivation centers on financial gain rather than state‑level espionage. Emerging from East Asia—particularly Japan—it has methodically expanded to Europe, Africa, and Southeast Asia by exploiting culturally relevant business themes such as payroll, tax, and invoicing in spearphishing campaigns. The adversary deploys a multi‑stage infection chain that begins with DLL side‑loading via legitimate, signed binaries and custom loaders like RomulusLoader and SilentRunLoader, which then drop remote access frameworks (Atlas RAT, ValleyRAT/Winos4.0). A distinguishing feature of TA4922 is its opportunistic use of third‑party Remote Management Software (RMS) such as AnyDesk and SyncFuture, first used as a benign front for initial persistence before pivoting to malicious activity. After installation the actor harvests credentials—particularly Google Chrome passwords, cookies and browsing data—using Python‑based payloads and exfiltrates them via HTTP POST calls to domains like ws.ztts88.cyou or direct C2 IP addresses on non‑standard ports. The use of ZIP archives titled in native languages (e.g., "電子請求書発行のお知らせ.zip") further obfuscates the malicious process, masking RAT dropper DLLs within seemingly legitimate attachments. TA4922 adapts swiftly to defensive measures; early indicators point toward rapid malware development possibly fueled by LLM‑assisted code generation. The group shifts communications to socially engineered out‑of‑band channels—including LINE, WhatsApp, and Microsoft Teams—to bypass traditional outbound filtering. Its persistence tactics rely on leveraging legitimate cloud hosting and trusted software to maintain footholds, while its broader operational footprint demonstrates a concerted push for data theft, fraud, and the resale of compromised accounts.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Government
Information technology
Manufacturing
Utilities

Targeted Countries / Regions

British Indian Ocean Territory
Germany
India
Indonesia
Italy
Japan
Malaysia
Singapore
South Africa
Taiwan
United Kingdom of Great Britain and Northern Ireland
CN
GB
DE
JP
IT
IN
TW
SG
KP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

TA4922 is a financially motivated actor proficient in business‑themed spearphishing and advanced DLL side‑loading techniques, enabling rapid delivery of RATs such as Atlas RAT and ValleyRAT across multiple regions. The group leverages legitimate remote management tools (AnyDesk, SyncFuture) for persistence and shifts communications to out‑of‑band platforms like LINE and WhatsApp to evade detection. Their operations exhibit a high tempo, frequent malware evolution, and a target spread that includes finance, healthcare, government, IT, manufacturing, and utilities worldwide.

Goals & Targeting

The core objective of TA4922 is monetization through data exfiltration and credential theft. By targeting sectors that routinely process sensitive personal and financial information—finance, healthcare, government, IT, manufacturing, utilities—the actor maximizes opportunities for fraud (credit‑card theft, account takeovers) and resale of stolen credentials on underground markets. Its business‑themed lures are tailored to regional languages and administrative contexts (e.g., tax authority impersonations in the UK or Southeast Asia), thus enhancing click‑through rates and reducing perceived risk among victims.

Enhanced Description

Key Capabilities

  • Business-themed spearphishing (HR, payroll, tax, invoicing)
  • DLL side-loading via signed binaries
  • Custom loader deployment (RomulusLoader, SilentRunLoader)
  • RAT installation (Atlas RAT, ValleyRAT/Winos4.0)
  • Credential phishing for fraud and data theft
  • Remote access through legitimate RMM tools (AnyDesk, SyncFuture)
  • Social engineering with spearphishing links and attachments
  • Out-of-band communication via LINE, WhatsApp, Microsoft Teams
  • ZIP archive delivery containing executables/DLLs
  • Direct IP C2 over non-standard ports
  • Google Chrome credential, cookie, browsing data theft
  • Exfiltration via HTTP POST to remote C2 server
  • Download and execution of secondary payloads
  • Upload of sensitive browser backup files to command & control
  • Impersonation of tax authorities or government benefits services

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Credential Access
Exfiltration
Persistence
Defense Evasion
Collection

ATT&CK Techniques

T1566.001
T1574.004
T1105
T1055
T1041
T1566.002
T1204
T1059.006
T1071.001

Software / Tooling

Atlas RAT
RomulusLoader
SilentRunLoader
ValleyRAT (Winos4.0)
AnyDesk
SyncFuture
HoldingHands

Campaigns & Victims

TA4922 demonstrates a rapid, modular campaign lifecycle that spans several continents within months of emergence. Campaigns launch with bulk spearphishing email threads crafted around regionally resonant business themes and often use ZIP attachments to smuggle DLL side‑loading dropper payloads. Once initial footholds are achieved, the actor leverages legitimate remote tools for persistence and expands data collection to include web browsers, credentials, and system configurations. Their operational tempo is high: new custom loaders (e.g., SilentRunLoader) appear within weeks of prior releases, and they consistently introduce improved exfiltration methods (HTTP POST to new domains). Victim selection shows a preference for organizations that handle monetary or personal data, indicating a calculated move towards lucrative targets.

IOC Patterns

  • business-themed spearphishing lures (HR/payroll/tax/invoicing)
  • DLL side-loading via signed binaries
  • custom loaders RomulusLoader/SilentRunLoader
  • remote management software hijacking (AnyDesk/SyncFuture)
  • ZIP archive delivery containing executable/DLL (e.g., 電子請求書発行のお知らせ.zip)
  • C2 IP 154.231.86.110 over TCP port 886
  • C2 domain ws.ztts88.cyou
  • IP 103.214.172.33 hosting secondary payloads
  • Chrome credential and cookie theft indicators

Recommended Actions

  • Implement advanced email filtering and spearphishing protection (DMARC, SPF, DKIM).
  • Conduct user education focusing on business-themed phishing risks.
  • Deploy application whitelisting and monitor for unauthorized DLL loading.
  • Monitor and audit the use of legitimate RMM tools such as AnyDesk and SyncFuture; restrict access to high‑privilege users only.
  • Block or quarantine known malicious IPs (154.231.86.110, 103.214.172.33) and domains (ws.ztts88.cyou).
  • Integrate anti‑malware solutions capable of detecting DLL side-loading and RAT behaviors.
  • Enforce least‑privilege policies for privileged accounts used in remote access tools.
  • Deploy network segmentation to limit lateral movement from infected hosts.

Suggested Tags

spearphishing
DLL-side-loading
custom-loader
RAT
remote-access-RMM
data-theft
credential-phishing-fraud
financially-motivated
Chinese-speaking-hacker
TA4922
Silver-Fox
Void-Arachne
remote-management-tool
china-based
japan-targeted
germany-targeted
atlas-rat
phishing
tax-authority-impersonation
browser-credential-theft
SilentRunLoader
ValleyRAT
python-malware
LLM-generated-code
rapid-development

Confidence Assessment

The available data indicates a high confidence in the core tactics and malware family usage of TA4922, supported by multiple independent observations. However, gaps remain regarding precise attribution timeline, internal organizational structure, and full extent of their operational tempo. Continued monitoring of evolving loaders and C2 domains is recommended to close these uncertainties.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.secureblink.com — Cited by web research for: Italy
  2. www.proofpoint.com — Cited by web research for: Payload
  3. securityonline.info — Cited by web research for: curl
  4. gurucul.com — Cited by web research for: Matrix
  5. https://ws.ztts88.cyou — Cited by AI analysis.
  6. https://mallory.ai — Cited by AI analysis.

Intel Summary

9

Techniques

46

Tools

0

Campaigns

59

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Phishing
Backdoor / C2
Data Exfiltration
spearphishing
DLL-side-loading
custom-loader
RAT
remote-access-RMM
data-theft
credential-phishing-fraud
financially-motivated
Chinese-speaking-hacker
TA4922
Silver-Fox
Void-Arachne
remote-management-tool
china-based
japan-targeted
germany-targeted
atlas-rat
phishing
tax-authority-impersonation
browser-credential-theft
SilentRunLoader
ValleyRAT
python-malware
LLM-generated-code
rapid-development

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
55%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.