Socprime
TA4922 Cybercrime Group Expands Malware Arsenal with New RATs and Loaders
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The cybercriminal group TA4922, identified as Chinese-speaking, has been deploying an expanding range of malware including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. These campaigns are financially motivated and target organizations across Japan, the UK, Germany, and Southeast Asia. The group's operational tempo is high, with tactics that blend custom malware with legitimate tools, complicating detection efforts. The attacks are characterized by their sophisticated planning and execution, raising alarms within the global security community. Current status indicates ongoing campaigns with no immediate resolution.
Key Points: • TA4922 is deploying a diverse malware arsenal including Atlas RAT and ValleyRAT. • The group targets organizations in multiple countries, including Japan and Germany. • Current operations are financially motivated and demonstrate high sophistication.