TA4922 is a Chinese-speaking cybercrime group known for localized HR, payroll, and tax-themed phishing emails targeting financial gain.
Analyst brief
TA4922 is a Chinese-speaking cybercrime cluster focused on financial gain. It targets organizations with localized phishing emails luring on HR, payroll, tax, and invoice themes, often impersonating trusted authorities. The group deploys various malware families such as Atlas RAT, RomulusLoader, and SilentRunLoader, and leverages social engineering to shift communication to messaging platforms. Defenders should be vigilant against emails with these themes, block suspicious attachments, and enforce multi-factor authentication to mitigate credential theft and remote access.
TA4922
unknown
TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware families, including Atlas RAT, RomulusLoader, and SilentRunLoader. The actor conducts targeted email campaigns, often impersonating trusted authorities, to facilitate credential phishing and fraud. TA4922's operational tempo is high, with a focus on obtaining remote access for financial gain, and it has shown a rapid evolution in its malware arsenal. The group is also noted for using social engineering to shift communications from email to messaging platforms, enhancing their phishing efforts.