news.mlab.sh
Back to the feed
threat-intel

China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

Medium
Summary

A China-linked cybercrime group, TA4922, has broadened its phishing attacks to include organizations in the UK, Germany, Italy, and South Africa. The group utilizes a constantly evolving arsenal of malware, including ValleyRAT and Atlas RAT, alongside newly developed tools, and increasingly relies on out-of-band communication channels to evade security controls. This expansion highlights the growing sophistication and global reach of cyber threats targeting financial gain.

TA4922, initially focused on East Asian targets, has significantly expanded its operational scope, now actively targeting organizations across Europe and Southeast Asia. The group’s tactics center around sophisticated phishing campaigns leveraging HR and business-related lures to deliver malware, including Atlas RAT, RomulusLoader, and SilentRunLoader. A key element of their strategy involves shifting communications from email to platforms like LINE, WhatsApp, and Microsoft Teams to bypass traditional security measures and facilitate data theft or malware deployment. The group’s financial motivation is evident in their focus on gaining remote access for data theft and resale.

Read the full article at The Hacker News