Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked TA4922 Broadens Cyber Attacks Globally

China-Linked TA4922 Broadens Cyber Attacks Globally

Posted on June 4, 2026 By CWS

In a concerning development, the cybercrime group known as TA4922, linked to China, has widened its scope to target organizations in the United Kingdom, Germany, Italy, and South Africa. According to cybersecurity firm Proofpoint, this group is employing a swift and evolving method of cyber attacks, utilizing a variety of malware including ValleyRAT, Atlas RAT, and new tools like RomulusLoader and SilentRunLoader.

Expansion of Cyber Attacks

TA4922, monitored by Proofpoint under this specific designation, is primarily recognized for its operations in East Asia. Although some connections to the cyber group Silver Fox exist, TA4922 is more focused on financial motives rather than espionage. The group’s main objective appears to be gaining unauthorized access to systems for data theft, fraudulent activities, and selling access to others.

Recently, TA4922 has shifted towards using phishing strategies with themes centered around human resources and business operations. These tactics aim to acquire credentials, commit fraud, and deploy malware, including Atlas RAT and SilentRunLoader. The group has also started to leverage alternative communication platforms like LINE, WhatsApp, and Microsoft Teams to evade corporate security measures.

Notable Cyber Campaigns

Several significant phishing campaigns by TA4922 have been observed. For instance, on March 6, 2026, Japanese firms were targeted with human resource-themed lures to deploy Atlas RAT. Similarly, organizations in the U.K. were attacked on March 30, 2026, using tax authority-related themes to install a Python-based loader, SilentRunLoader, which extracts sensitive data from web browsers.

Further attacks on April 2 and 10, 2026, focused on delivering malware through DLL side-loading, targeting companies in the U.K., Germany, and Southeast Asia. These incidents highlight the group’s ability to adapt and employ various lures to achieve their malicious objectives.

Global Cybersecurity Implications

Proofpoint emphasizes that while the primary intent of TA4922 appears financially driven, the malware’s capabilities could facilitate surveillance, potentially benefiting espionage entities. The international reach of TA4922 underscores the necessity for organizations worldwide to remain vigilant against sophisticated cyber threats that can expand rapidly and unpredictably.

As TA4922 continues to evolve and expand its operations, it serves as a stark reminder of the dynamic and borderless nature of cyber threats. Businesses must stay informed about these developments and bolster their cybersecurity defenses to mitigate potential risks.

The Hacker News Tags:China, cyber threats, Cybercrime, Cybersecurity, Europe, Malware, phishing attacks, Proofpoint, South Africa, TA4922

Post navigation

Previous Post: CISA Alerts on Critical Android Vulnerability Being Exploited
Next Post: Critical Vulnerability in Mirasvit Cache Warmer Exposed

Related Posts

Critical 18-Year NGINX Vulnerability Enables Remote Code Execution Critical 18-Year NGINX Vulnerability Enables Remote Code Execution The Hacker News
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices The Hacker News
Open Source Web Application Firewall with Zero-Day Detection and Bot Protection Open Source Web Application Firewall with Zero-Day Detection and Bot Protection The Hacker News
EngageLab SDK Vulnerability Risks Millions of Android Users EngageLab SDK Vulnerability Risks Millions of Android Users The Hacker News
Microsoft Patches SharePoint Zero-Day and 168 Security Flaws Microsoft Patches SharePoint Zero-Day and 168 Security Flaws The Hacker News
Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally
  • CISA Alerts on Critical Android Vulnerability Being Exploited
  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally
  • CISA Alerts on Critical Android Vulnerability Being Exploited
  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark