2026-08-28NOTABLEA China-nexus financially-motivated cluster already tracked for EU expansion picks up a commodity, Telegram-proliferated RAT
TA4922
actor · actor:ta4922 single-source
TA4922, China-nexus financially-motivated cluster; Atlas RAT/RomulusLoader/SilentRunLoader, expands to DE/UK/IT
Coverage
4
first 2026-06-05 → last 2026-08-28
Latest activity
2026-08-28
A China-nexus financially-motivated cluster already tracked for EU expansion picks up a commodity…
Peak priority
high
1 high · 3 notable
Targets
finance
sectors: finance, public-sector, healthcare · regions: apac, europe, dach
Sources cited
7
6 hosts
2026-06-054 appearances2026-08-28
Defender insights
What each entry about TA4922 tells a defender to do, newest first.
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- CruciferraProofpoint attributes four Cruciferra-packed AsyncRAT campaigns to TA4922
Story timeline
- 2026-08-28TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit, dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India
- 2026-07-21Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA4922
- 2026-06-18China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network
- 2026-06-05Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
Hunting pivots
ATT&CK techniques (11 across 8 tactics)
11 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionHijack Execution Flow: DLL
- PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationProcess Injection · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Obfuscated Files or Information: Software Packing · Process Injection · Hijack Execution Flow: DLL · Reflective Code Loading
- Defense ImpairmentDisable or Modify Tools
- Credential AccessInput Capture: Keylogging · Credentials from Password Stores: Credentials from Web Browsers
- CollectionInput Capture: Keylogging · Screen Capture
- Command and ControlIngress Tool Transfer
Execution TA0002
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗
Persistence TA0003
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
Privilege Escalation TA0004
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗
T1027.002Obfuscated Files or Information: Software Packing×1
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.
Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗
Credential Access TA0006
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗
Collection TA0009
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗
Entries about TA4922 (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- proofpoint.com2 (29%)
- bleepingcomputer.com1 (14%)
- cert.org.cn1 (14%)
- infosecurity-magazine.com1 (14%)
- news.risky.biz1 (14%)
- thehackernews.com1 (14%)
All cited sources (7)
- bleepingcomputer.comBleepingComputer, 2026-06-04https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/
- cert.org.cnCNCERT/CChttps://www.cert.org.cn/publish/main/10/2026/20260522113326926111046/20260522113326926111046_.html
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/
- news.risky.bizRisky Biz Newshttps://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/
- proofpoint.comProofpointhttps://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient
- proofpoint.comProofpoint Threat Insighthttps://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service
- thehackernews.comThe Hacker News, 2026-06-04https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html