Also known as: tracked as, tax professionals, corporate finance teams, data theft, Italy, the United Kingdom, South Africa, Silver Fox, Void Arachne, ValleyRAT, control capabilities after compromise
TA4922 is a sophisticated threat actor whose primary motivation centers on financial gain rather than state‑level espionage. Emerging from East Asia—particularly Japan—it has methodically expanded to Europe, Africa, and Southeast Asia by exploiting culturally relevant business themes such as payroll, tax, and invoicing in spearphishing campaigns. The adversary deploys a multi‑stage infection chain that begins with DLL side‑loading via legitimate, signed binaries and custom loaders like RomulusLoader and SilentRunLoader, which then drop remote access frameworks (Atlas RAT, ValleyRAT/Winos4.0). A distinguishing feature of TA4922 is its opportunistic use of third‑party Remote Management Software (RMS) such as AnyDesk and SyncFuture, first used as a benign front for initial persistence before pivoting to malicious activity. After installation the actor harvests credentials—particularly Google Chrome passwords, cookies and browsing data—using Python‑based payloads and exfiltrates them via HTTP POST calls to domains like ws.ztts88.cyou or direct C2 IP addresses on non‑standard ports. The use of ZIP archives titled in native languages (e.g., "電子請求書発行のお知らせ.zip") further obfuscates the malicious process, masking RAT dropper DLLs within seemingly legitimate attachments. TA4922 adapts swiftly to defensive measures; early indicators point toward rapid malware development possibly fueled by LLM‑assisted code generation. The group shifts communications to socially engineered out‑of‑band channels—including LINE, WhatsApp, and Microsoft Teams—to bypass traditional outbound filtering. Its persistence tactics rely on leveraging legitimate cloud hosting and trusted software to maintain footholds, while its broader operational footprint demonstrates a concerted push for data theft, fraud, and the resale of compromised accounts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TA4922 is a financially motivated actor proficient in business‑themed spearphishing and advanced DLL side‑loading techniques, enabling rapid delivery of RATs such as Atlas RAT and ValleyRAT across multiple regions. The group leverages legitimate remote management tools (AnyDesk, SyncFuture) for persistence and shifts communications to out‑of‑band platforms like LINE and WhatsApp to evade detection. Their operations exhibit a high tempo, frequent malware evolution, and a target spread that includes finance, healthcare, government, IT, manufacturing, and utilities worldwide.
Goals & Targeting
The core objective of TA4922 is monetization through data exfiltration and credential theft. By targeting sectors that routinely process sensitive personal and financial information—finance, healthcare, government, IT, manufacturing, utilities—the actor maximizes opportunities for fraud (credit‑card theft, account takeovers) and resale of stolen credentials on underground markets. Its business‑themed lures are tailored to regional languages and administrative contexts (e.g., tax authority impersonations in the UK or Southeast Asia), thus enhancing click‑through rates and reducing perceived risk among victims.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA4922 demonstrates a rapid, modular campaign lifecycle that spans several continents within months of emergence. Campaigns launch with bulk spearphishing email threads crafted around regionally resonant business themes and often use ZIP attachments to smuggle DLL side‑loading dropper payloads. Once initial footholds are achieved, the actor leverages legitimate remote tools for persistence and expands data collection to include web browsers, credentials, and system configurations. Their operational tempo is high: new custom loaders (e.g., SilentRunLoader) appear within weeks of prior releases, and they consistently introduce improved exfiltration methods (HTTP POST to new domains). Victim selection shows a preference for organizations that handle monetary or personal data, indicating a calculated move towards lucrative targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data indicates a high confidence in the core tactics and malware family usage of TA4922, supported by multiple independent observations. However, gaps remain regarding precise attribution timeline, internal organizational structure, and full extent of their operational tempo. Continued monitoring of evolving loaders and C2 domains is recommended to close these uncertainties.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
46
Tools
0
Campaigns
59
IOCs
0
Observed Data
5
Tactics