TA4922 Cybercrime Group Expands Malware Arsenal with New RATs and Loaders

TA4922 Cybercrime Group Expands Malware Arsenal with New RATs and Loaders

First seen 4 Jun 2026, 16:54 UTC GbhackersCybersecuritynewsSocprime 86% similarity 60.5

Article Content

Browse articles
ThreatCluster

The cybercriminal group TA4922, identified as Chinese-speaking, has been deploying an expanding range of malware including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. These campaigns are financially motivated and target organizations across Japan, the UK, Germany, and Southeast Asia. The group's operational tempo is high, with tactics that blend custom malware with legitimate tools, complicating detection efforts. The attacks are characterized by their sophisticated planning and execution, raising alarms within the global security community. Current status indicates ongoing campaigns with no immediate resolution.

Key Points: • TA4922 is deploying a diverse malware arsenal including Atlas RAT and ValleyRAT. • The group targets organizations in multiple countries, including Japan and Germany. • Current operations are financially motivated and demonstrate high sophistication.

ThreatCluster AI

Timeline

2026-06-04
Proofpoint reports on TA4922's activities
Proofpoint identifies TA4922's deployment of new malware tools, including Atlas RAT and RomulusLoader, affecting organizations globally.
Gbhackers
2026-06-04
Global security community alerted
Cybersecuritynews highlights the growing threat from TA4922's sophisticated cybercrime campaigns targeting various countries.
Cybersecuritynews

Community

Browse all →