← All Threat Actors
Threat Actor Profile

TA4922

No known aliases in database
⚠ Critical Threat
Global Operational Expansion, Localized Business Lure Campaign
Origin China
Motivation financial gain (specifically fraud, data theft, and the resale of network access)

Target Sectors

Corporate/Enterprise environments Financial services Healthcare Government/Tax authorities (impersonated) Education Manufacturing

Known TTPs

Highly localized social engineering (impersonating HR, payroll, tax, and invoicing)
Platform pivoting (moving victims from email to WhatsApp, LINE, or Microsoft Teams)
DLL sideloading
Credential phishing
Malware delivery via weaponized ZIP files
Deployment of modular backdoors (Atlas RAT)
Use of loaders (RomulusLoader, SilentRunLoader)
Use of crypter-as-a-service (Cruciferra)
Use of disposable email accounts (Outlook, Hotmail, Gmail)

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD