China's TA4922 Expands Cybercrime Attacks Globally
China's TA4922 cybercrime group has significantly expanded its operations globally, targeting a diverse range of countries and employing a wider array of tactics and techniques than previously observed. Initially focused on tax-themed phishing in Japan, the group now targets East Asia, Europe, and South Africa with sophisticated lure emails and diverse attack chains, often utilizing RATs like ValleyRAT and Atlas RAT. The group's deliberate obfuscation of malware and overlaps with the Silver Fox threat actor are creating challenges for analysts, highlighting the evolving nature of cyber threats.
TA4922, a prolific cybercrime group originating from China, has undergone a dramatic expansion of its operations over the past two months. Initially concentrated on targeting Japanese organizations with tax-related phishing campaigns and utilizing ValleyRAT for remote access, the group’s activities have broadened considerably, encompassing a multitude of countries across East Asia, Europe, and Africa. This expansion is characterized by a significantly wider range of TTPs, including the use of disposable email addresses, leveraging less-monitored communication platforms like Microsoft Teams and WhatsApp, and employing diverse malware delivery methods, from malicious links to archive files containing RATs. The group’s adaptability and indiscriminate targeting are concerning, as evidenced by its use of lures in multiple languages and dialects tailored to local norms.
The group’s attack chains are particularly complex, often involving the initial deployment of a phishing email followed by the delivery of malware via file-sharing services or DLL sideloading. They frequently utilize legitimate RMM software like AnyDesk, employing loaders like RomulusLoader and SilentRunLoader to deliver payloads, with SilentRunLoader itself acting as a Google Chrome stealer. The group’s deliberate obfuscation of malware, requiring further analysis to identify families like Atlas RAT and ValleyRAT variants, is a key element of their strategy. Recent research has also revealed significant overlaps between TA4922 and the Silver Fox threat actor, a Chinese state-associated group, further complicating attribution and analysis.
This expansion highlights the increasing sophistication and global reach of cybercrime operations. The group’s ability to adapt its tactics and leverage diverse tools underscores the need for organizations to adopt layered security measures and maintain vigilance against evolving threats. The connection to Silver Fox raises concerns about potential state-sponsored activity and the blurring lines between espionage and financially motivated cybercrime.
