#ta4922
China‑linked #TA4922 phishing campaign now targets the #Europe and #Africa, spreading evolving malware that threatens regional cyber security. #CyberRisk #Geopolitics https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
TA4922 expanded targeting to organizations in the U.K., Germany, Italy, and South Africa while continuing campaigns against East Asia.
thehackernews.com
June 5, 2026 at 5:18 PM
Our new @threatinsight report is a comprehensive overview of TA4922, a newly designated Chinese-speaking, financially motivated threat actor that largely targets East Asia.

It currently conducts more unique campaigns than any other cybercriminal we track. www.proofpoint.com/us/blog/thre...
TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US
Key Findings: TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal. The group has been
www.proofpoint.com
June 3, 2026 at 3:15 PM
TA4922: il gruppo cinese che ha deciso di fare sul serio in Europa – e l’Italia è nel mirino

📌 Link all'articolo : www.redhotcyber.com/post/ta4922-...

A cura di Luca Stivali del gruppo DarkLab

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #spearphishing
June 7, 2026 at 6:53 AM
Proofpoint researchers discovered a RAT framework called PackClient, which is used by at least one threat actor - Chinese-speaking TA4922 - is sold on Telegram, and supports data theft, surveillance, and downloading of additional plugins and payloads. www.proofpoint.com/us/blog/thre...
August 28, 2026 at 8:12 AM
Breaking down China linked cybercriminal group
#china #cybersecurity #cyberattacks #threatintel
TA4922 Modus Operandi Assessment open.substack.com/pub/cyberwar...
TA4922 Modus Operandi Assessment
TA4922 is a financially motivated Chinese-speaking cybercrime
open.substack.com
June 5, 2026 at 3:17 PM
TA4922, a Chinese-speaking threat group, is expanding globally with Atlas RAT, RomulusLoader, and ValleyRAT. It uses HR, payroll, and invoicing lures, plus DLL sideloading and trusted tools, to drive fraud across East Asia, Europe, and Africa. #China
TA4922: The Suspected Chinese Crime Group is Going Global
TA4922 is a highly active Chinese-speaking threat actor that has evolved its toolkit to include Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT/Winos4.0 while using regional HR, payroll, tax, and invoicing lures to target organizations across East Asia, Europe, and Africa. The group combines DLL sideloading, cloud hosting, trusted tools like AnyDesk and...
www.hendryadrian.com
June 3, 2026 at 4:00 PM
China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
thehackernews.com
June 4, 2026 at 12:40 PM
TA4922, a Chinese-speaking potatocrime group, is accelerating campaigns across Asia, Europe, and South Africa using phishing, social engineering, and RAT malware to steal credentials and data. #China #TA4922 #ValleyRAT
June 4, 2026 at 1:30 PM
📣🚨 China-linked #TA4922 hackers are targeting UK and European organisations with tax and benefits phishing lures, new malware tools, and #SilentRunLoader, a Python-based stealer linked to LLM-assisted development.

Read: hackread.com/china-ta4922...

#CyberSecurity #Malware #Phishing #UK #Europe
China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware
TA4922, a suspected China aligned cybercrime group, is targeting UK and European organisations with tax, payroll and benefits themed malware campaigns.
hackread.com
June 3, 2026 at 1:38 PM
Proofpoint has observed a Chinese-speaking threat actor (TA4922) using a command and control (C2) framework called PackClient.

The framework enables data theft, surveillance, and downloading of additional plugins and payloads.

Blog: www.proofpoint.com/us/blog/thre...

#impersonation #phishing
August 27, 2026 at 5:47 PM
--Peptide promoters seek to poison chatbots by Reddit postings,
--Two-thirds of banned Anthropic accounts were making malware,
--US sanctions Iranian crypto exchange Nobitex,
--HTTP/2 Bomb DoS can take down a machine in seconds,
--Chinese cybercrime group TA4922 is now targeting Europe, 3/5
June 4, 2026 at 1:36 PM
Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco
il blog: insicurezzadigitale.com/cruciferra-i...

#cybersecurity #byovd #cruciferra #crypter #edr #edrkiller #infosec #malware #processghosting #ta4922 #trojan
July 24, 2026 at 8:04 AM
TA4922, a Chinese-speaking cybercrime group, is accelerating campaigns across Asia, Europe, and South Africa using phishing, social engineering, and RAT malware to steal credentials and data. #China #TA4922 #ValleyRAT
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
TA4922 is a Chinese-speaking cybercrime group that has expanded its operations across Asia, Europe, and South Africa by using social engineering, phishing, and multiple malware families to gain access to victim organizations. Proofpoint says the group is financially motivated and has used tools like Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT in...
www.hendryadrian.com
June 4, 2026 at 1:30 PM
Tämä ei tämän hetken tietojen valossa liity Kiinan hallintoon, mutta on huomioitavaa, että kiinalainen kyberrikostoimija TA9422 on Proofpointin raportin mukaan laajentanut toimintaansa Eurooppaan ja Afrikkaan.

www.proofpoint.com/us/blog/thre...
TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US
Key Findings: TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal. The group has been
www.proofpoint.com
June 5, 2026 at 6:22 AM
TA4922 (China-linked) expands to Italy, UK, Germany with phishing. New malware: SilentRunLoader, RomulusLoader. Financial lures, local-language emails. Update email filters + monitor endpoint RAT behavior. Alert level: HIGH. Sources: Proofpoint, Dark Reading.
June 8, 2026 at 6:14 PM
8/ That's your Friday briefing. Patch your SharePoint. Watch TA4922. Argentina is finally building cyber infrastructure. And Airbnb's CEO thinks frontier AI labs are missing the point. Hard to disagree. 🙏 #TechNews #Cybersecurity #AI #InfoSec #LATAM
June 5, 2026 at 4:21 PM
Chinese Cybercrime Group in Spotlight for Record Campaign Pace Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities. The post ...

#cybercrime #Malware #& #Threats #China #Cybercrime #TA4922

Origin | Interest | Match
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
event.on24.com
June 4, 2026 at 11:35 AM
確定申告に要注意——新型マルウェア「PackClient」、税務調査を装い世界の企業を狙う

Proofpointが観測、TelegramでRAT「PackClient」が販売され、TA4922が使用中国とインドで税務当局を騙るメールを送りつけ、PackClientのインストーラーを配布高度な機能を備えたRAT、研究者はアジア圏を超えた拡散を警告中国のハッカーたちが、ここ約3カ月にわたり、高度なリモートア
確定申告に要注意——新型マルウェア「PackClient」、税務調査を装い世界の企業を狙う
Proofpointが観測、TelegramでRAT「PackClient」が販売され、TA4922が使用中国とインドで税務当局を騙るメールを送りつけ、PackClientのインストーラーを配布高度な機能を備えたRAT、研究者はアジア圏を超えた拡散を警告中国のハッカーたちが、ここ約3カ月にわたり、高度なリモートア
blackhatnews.tokyo
September 1, 2026 at 3:19 PM
中国系ハッカー、税金をテーマにしたフィッシング攻撃でPackClient RATを展開しデータを窃取

中国語話者の脅威アクターTA4922が、中国本土とインドの組織を標的とした税金をテーマにしたフィッシングキャンペーンを通じて、リモートアクセス型トロイの木馬「PackClient」を展開していることが分かりました。 Proofpointが2026年5月と7月に観測したこの活動は、同グループの初期アクセス能力の拡大と、...
中国系ハッカー、税金をテーマにしたフィッシング攻撃でPackClient RATを展開しデータを窃取
中国語話者の脅威アクターTA4922が、中国本土とインドの組織を標的とした税金をテーマにしたフィッシングキャンペーンを通じて、リモートアクセス型トロイの木馬「PackClient」を展開していることが分かりました。 Proofpointが2026年5月と7月に観測したこの活動は、同グループの初期アクセス能力の拡大と、
blackhatnews.tokyo
August 30, 2026 at 4:02 PM
@proofpoint.com
TA4922 used tax-themed phishing to deliver PackClient, a modular RAT enabling surveillance, theft and payload deployment.
-
IOCs: gov12366[.]com, 206[.]238[.]196[.]96:6666, 64[.]81[.]30[.]99
-
#Malware #ThreatActor #ThreatIntel
TA4922 Deploys PackClient RAT
www.proofpoint.com
August 29, 2026 at 1:14 PM