Threat Actor ๐จ๐ณ China
TA4922
TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware families, including Atlas RAT, RomulusLoader, and SilentRunLoader. The actor conducts targeted email campaigns, often impersonating trusted authorities, to facilitate credential phishing and fraud. TA4922's operational tempo is high, with a focus on obtaining remote access for financial gain, and it has shown a rapid evolution in its malware arsenal. The group is also noted for using social engineering to shift communications from email to messaging platforms, enhancing their phishing efforts.
Indicators of Compromise 2
MITRE ATT&CK TTPs 12
T1006 T1012 T1014 T1053.005 T1055 T1055.015 T1068 T1070.004 T1071.001 T1082 T1204.002 T1548.002
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
ListPlanting
Defense Evasion
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Web Protocols
Command And Control
System Information Discovery
Discovery
Malicious File
Execution
Bypass User Account Control
Privilege Escalation