Chinese hackers use new Atlas RAT malware in European cyberattacks
A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The group’s financially motivated attacks involve sophisticated phishing campaigns and a diverse arsenal of tools, raising concerns about potential surveillance capabilities and overlap with espionage activities. Proofpoint researchers have identified multiple malware families utilized by the group, highlighting the need for enhanced detection and response measures.
TA4922, previously active in East Asia, has significantly broadened its attack surface, now focusing on targets in Germany, Italy, the United Kingdom, South Africa, and Southeast Asia. The group’s tactics involve highly targeted phishing emails mimicking payroll notices, tax audits, and other official communications, leveraging platforms like WhatsApp, LINE, and Microsoft Teams to lure victims. Since March, the group has exhibited a dramatically increased tempo and operational diversity, making it the most active cybercrime threat actor tracked by Proofpoint. The group’s malware capabilities extend beyond simple data theft, potentially including surveillance, which could be attractive to espionage groups. The use of large language models (LLMs) in malware development, evidenced by placeholder values and AI-generated code patterns, represents a concerning trend.