FlagThis
← Threat Actors
/
China
/
TA4922
DOSSIER // TA4922
TA4922
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
China
Primary Aliases:
No secondary vendor aliases recorded.
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
financial gain (specifically fraud, data theft, and the resale of network access)
Active Timeline
Unknown – Present
Confidence Rating
90% (Grounded)
Global Operational Expansion, Localized Business Lure Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Corporate/Enterprise environments
Financial services
Healthcare
Government/Tax authorities (impersonated)
Education
Manufacturing
🛡️ MITRE ATT&CK® Attack Lifecycle
(9 TTPs)
📥 Download Navigator JSON
All Stages
9
Initial Access
1
Credential Access & Discovery
1
Command & Control
1
Operational Techniques
6
Initial Access
1
T1566
Credential phishing
↗
Credential Access & Discovery
1
T1003
Highly localized social engineering (impersonating HR, payroll, tax, and invoicing)
↗
Command & Control
1
T1071
Deployment of modular backdoors (Atlas RAT)
↗
Operational Techniques
6
T1000
Platform pivoting (moving victims from email to WhatsApp, LINE, or Microsoft Teams)
↗
T1000
DLL sideloading
↗
T1000
Malware delivery via weaponized ZIP files
↗
T1000
Use of loaders (RomulusLoader, SilentRunLoader)
↗
T1000
Use of crypter-as-a-service (Cruciferra)
↗
T1000
Use of disposable email accounts (Outlook, Hotmail, Gmail)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
TA4922 Deployment of Atlas RAT Malware via Silver Fox Campaign
Attacks and Vulnerabilities
2026-06-04
Adversary Rosetta Stone // TA4922
×
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD