Frequency
3
occurrences
First Seen
June 4, 2026
Last Seen
September 1, 2026
Related Threat Clusters
-
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026 -
PackClient RAT Targets Global Firms via Tax Phishing Campaigns
TA4922, a financially motivated threat actor, has been distributing the PackClient RAT since late May 2026, primarily targeting organizations in China and India. The malware is delivered through spoofed emails claiming…
3 articles · Updated September 1, 2026 -
TA4922 Cybercrime Group Expands Malware Arsenal with New RATs and Loaders
The cybercriminal group TA4922, identified as Chinese-speaking, has been deploying an expanding range of malware including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. These campaigns are financially…
3 articles · Updated June 4, 2026
Recent Intelligence Reports
- Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures — Techradar · September 1, 2026
- Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity-Magazine · July 20, 2026
- Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT — Cybersecuritynews · June 4, 2026