Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked TA4922 Broadens Cyber Attacks Globally

China-Linked TA4922 Broadens Cyber Attacks Globally

Posted on June 4, 2026 By CWS

In a concerning development, the cybercrime group known as TA4922, linked to China, has widened its scope to target organizations in the United Kingdom, Germany, Italy, and South Africa. According to cybersecurity firm Proofpoint, this group is employing a swift and evolving method of cyber attacks, utilizing a variety of malware including ValleyRAT, Atlas RAT, and new tools like RomulusLoader and SilentRunLoader.

Expansion of Cyber Attacks

TA4922, monitored by Proofpoint under this specific designation, is primarily recognized for its operations in East Asia. Although some connections to the cyber group Silver Fox exist, TA4922 is more focused on financial motives rather than espionage. The group’s main objective appears to be gaining unauthorized access to systems for data theft, fraudulent activities, and selling access to others.

Recently, TA4922 has shifted towards using phishing strategies with themes centered around human resources and business operations. These tactics aim to acquire credentials, commit fraud, and deploy malware, including Atlas RAT and SilentRunLoader. The group has also started to leverage alternative communication platforms like LINE, WhatsApp, and Microsoft Teams to evade corporate security measures.

Notable Cyber Campaigns

Several significant phishing campaigns by TA4922 have been observed. For instance, on March 6, 2026, Japanese firms were targeted with human resource-themed lures to deploy Atlas RAT. Similarly, organizations in the U.K. were attacked on March 30, 2026, using tax authority-related themes to install a Python-based loader, SilentRunLoader, which extracts sensitive data from web browsers.

Further attacks on April 2 and 10, 2026, focused on delivering malware through DLL side-loading, targeting companies in the U.K., Germany, and Southeast Asia. These incidents highlight the group’s ability to adapt and employ various lures to achieve their malicious objectives.

Global Cybersecurity Implications

Proofpoint emphasizes that while the primary intent of TA4922 appears financially driven, the malware’s capabilities could facilitate surveillance, potentially benefiting espionage entities. The international reach of TA4922 underscores the necessity for organizations worldwide to remain vigilant against sophisticated cyber threats that can expand rapidly and unpredictably.

As TA4922 continues to evolve and expand its operations, it serves as a stark reminder of the dynamic and borderless nature of cyber threats. Businesses must stay informed about these developments and bolster their cybersecurity defenses to mitigate potential risks.

The Hacker News Tags:China, cyber threats, Cybercrime, Cybersecurity, Europe, Malware, phishing attacks, Proofpoint, South Africa, TA4922

Post navigation

Previous Post: CISA Alerts on Critical Android Vulnerability Being Exploited
Next Post: Critical Vulnerability in Mirasvit Cache Warmer Exposed

Related Posts

Trusted Open Source Insights: AI and Security Trends Trusted Open Source Insights: AI and Security Trends The Hacker News
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign The Hacker News
DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes The Hacker News
AI Security Concerns in Amazon Bedrock and Other Platforms AI Security Concerns in Amazon Bedrock and Other Platforms The Hacker News
F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion F5 Breach Exposes BIG-IP Source Code — Nation-State Hackers Behind Massive Intrusion The Hacker News
Entra ID Data Protection: Essential or Overkill? Entra ID Data Protection: Essential or Overkill? The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark