Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked TA4922 Broadens Cyber Attacks Globally

China-Linked TA4922 Broadens Cyber Attacks Globally

Posted on June 4, 2026 By CWS

In a concerning development, the cybercrime group known as TA4922, linked to China, has widened its scope to target organizations in the United Kingdom, Germany, Italy, and South Africa. According to cybersecurity firm Proofpoint, this group is employing a swift and evolving method of cyber attacks, utilizing a variety of malware including ValleyRAT, Atlas RAT, and new tools like RomulusLoader and SilentRunLoader.

Expansion of Cyber Attacks

TA4922, monitored by Proofpoint under this specific designation, is primarily recognized for its operations in East Asia. Although some connections to the cyber group Silver Fox exist, TA4922 is more focused on financial motives rather than espionage. The group’s main objective appears to be gaining unauthorized access to systems for data theft, fraudulent activities, and selling access to others.

Recently, TA4922 has shifted towards using phishing strategies with themes centered around human resources and business operations. These tactics aim to acquire credentials, commit fraud, and deploy malware, including Atlas RAT and SilentRunLoader. The group has also started to leverage alternative communication platforms like LINE, WhatsApp, and Microsoft Teams to evade corporate security measures.

Notable Cyber Campaigns

Several significant phishing campaigns by TA4922 have been observed. For instance, on March 6, 2026, Japanese firms were targeted with human resource-themed lures to deploy Atlas RAT. Similarly, organizations in the U.K. were attacked on March 30, 2026, using tax authority-related themes to install a Python-based loader, SilentRunLoader, which extracts sensitive data from web browsers.

Further attacks on April 2 and 10, 2026, focused on delivering malware through DLL side-loading, targeting companies in the U.K., Germany, and Southeast Asia. These incidents highlight the group’s ability to adapt and employ various lures to achieve their malicious objectives.

Global Cybersecurity Implications

Proofpoint emphasizes that while the primary intent of TA4922 appears financially driven, the malware’s capabilities could facilitate surveillance, potentially benefiting espionage entities. The international reach of TA4922 underscores the necessity for organizations worldwide to remain vigilant against sophisticated cyber threats that can expand rapidly and unpredictably.

As TA4922 continues to evolve and expand its operations, it serves as a stark reminder of the dynamic and borderless nature of cyber threats. Businesses must stay informed about these developments and bolster their cybersecurity defenses to mitigate potential risks.

The Hacker News Tags:China, cyber threats, Cybercrime, Cybersecurity, Europe, Malware, phishing attacks, Proofpoint, South Africa, TA4922

Post navigation

Previous Post: CISA Alerts on Critical Android Vulnerability Being Exploited
Next Post: Critical Vulnerability in Mirasvit Cache Warmer Exposed

Related Posts

GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads GhostPoster Malware Found in 17 Firefox Add-ons with 50,000+ Downloads The Hacker News
Cybersecurity Threats: Game Cheat Spyware and More Cybersecurity Threats: Game Cheat Spyware and More The Hacker News
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS The Hacker News
AI Browsers Vulnerable to Phishing Attacks: A Security Concern AI Browsers Vulnerable to Phishing Attacks: A Security Concern The Hacker News
APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark