CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

TA4922

actor · actor:ta4922 single-source

TA4922, China-nexus financially-motivated cluster; Atlas RAT/RomulusLoader/SilentRunLoader, expands to DE/UK/IT

Coverage
4
first 2026-06-05 → last 2026-08-28
Latest activity
2026-08-28
A China-nexus financially-motivated cluster already tracked for EU expansion picks up a commodity…
Peak priority
high
1 high · 3 notable
Targets
finance
sectors: finance, public-sector, healthcare · regions: apac, europe, dach
Sources cited
7
6 hosts
2026-06-054 appearances2026-08-28

Defender insights

What each entry about TA4922 tells a defender to do, newest first.

2026-08-28NOTABLEA China-nexus financially-motivated cluster already tracked for EU expansion picks up a commodity, Telegram-proliferated RAT

Triage

2026-07-21NOTABLEProofpoint details Cruciferra, a commercial crypter that hides payloads with process ghosting and kills EDR via a vulnerable signed driver

Triage

2026-06-18NOTABLEChina arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

Story timeline

  1. 2026-08-28TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit, dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India
    active-threatsA China-nexus financially-motivated cluster already tracked for EU expansion picks up a commodity, Telegram-proliferated RAT
  2. 2026-07-21Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA4922
    active-threatsProofpoint details Cruciferra, a commercial crypter that hides payloads with process ghosting and kills EDR via a vulnerable signed driver
  3. 2026-06-18China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network
    active-threats
  4. 2026-06-05Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
    active-threats
ATT&CK techniques (11 across 8 tactics)

11 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ExecutionHijack Execution Flow: DLL
  • PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationProcess Injection · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information · Obfuscated Files or Information: Software Packing · Process Injection · Hijack Execution Flow: DLL · Reflective Code Loading
  • Defense ImpairmentDisable or Modify Tools
  • Credential AccessInput Capture: Keylogging · Credentials from Password Stores: Credentials from Web Browsers
  • CollectionInput Capture: Keylogging · Screen Capture
  • Command and ControlIngress Tool Transfer

Execution TA0002

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

Privilege Escalation TA0004

T1055Process Injection×1

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗

T1027.002Obfuscated Files or Information: Software Packing×1

Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.

Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗

T1055Process Injection×1

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd · ATT&CK page ↗

Credential Access TA0006

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

T1555.003Credentials from Password Stores: Credentials from Web Browsers×1

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-06-05/proofpoint-ta4922-a-china-nexus-cybercrime-cluster-expands-f · ATT&CK page ↗

Collection TA0009

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-28/ta4922-packclient-telegram-rat-tax-lures · ATT&CK page ↗

Entries about TA4922 (4)

2026-08-28 · view entry permalink →

NOTABLENATOB2

TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit, dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India

Proofpoint documents PackClient, a modular remote-access trojan and command-and-control framework actively sold on Telegram, now in use by TA4922, an already-tracked China-nexus, financially-motivated cluster, previously associated with Atlas RAT, RomulusLoader and SilentRunLoader and reported in June as expanding its targeting to the UK, Germany, Italy and South Africa (The Hacker News, 2026-06-04). Proofpoint writes that "with this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem" (Proofpoint, 2026-08-27).

PackClient's delivery chain uses rundll32 execution and reflective DLL loading, with persistence via a registry RunOnce key, and stores its configuration under HKCU\SOFTWARE\PackClientConsole. Proofpoint's hunting guidance lists, as separate items, a "Distinct Rundll32 command line used to launch PackClient.", "PackClient config stored in registry (HKCU\SOFTWARE\PackClientConsole\)." and a "Distinct process tree and command line flags" (Proofpoint, 2026-08-27). It supports keylogging, webcam and screen capture, file exfiltration and plugin/payload management over dual C2 channels using a custom TCP protocol with distinctive handshake byte sequences (Proofpoint names them PLH1/PLC1): "PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads" (Proofpoint, 2026-08-27).

In the observed campaigns TA4922 used tax-themed phishing lures against organisations in mainland China and India, with post-compromise activity that included deploying ManageEngine remote-monitoring-and-management tooling, a legitimate RMM abused for continued access, consistent with this actor's established pattern of using commodity or legitimate management tools post-compromise. Proofpoint does not name a MITRE ATT&CK technique explicitly, but the described behaviours map to registry Run-key persistence, DLL side-loading/reflective loading defence evasion, and collection via keylogging and screen capture.

The campaign targeting is mainland China and India, not this constituency's home region or profiled sectors directly, but the relevance rests on two points: TA4922 was reported in June 2026 as expanding its targeting to the UK, Germany, Italy and South Africa (The Hacker News, 2026-06-04), so a new Telegram-proliferated C2 framework in this actor's toolkit is transferable tradecraft to watch for; and a MaaS tool sold on Telegram is not exclusive to one actor and may surface again against a different, more directly-relevant target set. Triage: a registry key at HKCU\SOFTWARE\PackClientConsole on any endpoint has no legitimate application association and is a direct compromise indicator; process trees showing rundll32 launched with non-standard command-line flags followed by reflective DLL-loading behaviour (no corresponding file on disk for the loaded module) are the discriminator against ordinary rundll32 usage, which normally loads a named, on-disk DLL export.

With this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem.

PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads.

Distinct Rundll32 command line used to launch PackClient.

PackClient config stored in registry (HKCU\\SOFTWARE\\PackClientConsole\\).

Distinct process tree and command line flags

Proofpoint 2026-08-27

Builds on: Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and…

threat28 Aug 06:38Zsingle-sourceOpen finding →

2026-07-21 · view entry permalink →

NOTABLENATOB2

Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA4922

Proofpoint's analysis details Cruciferra, a Mono/.NET-based crypter-as-a-service advertised on underground forums since late 2025 and used by several unrelated criminal groups to pack commodity payloads (AsyncRAT/DCRAT, Agent Tesla, XWorm, Formbook/XLoader, Remcos, Snake Keylogger and others). Its distinguishing feature is an evasion stack aimed squarely at endpoint defenses (Proofpoint, 2026-07-20). Payloads are encrypted with one of over 90 polymorphic cipher routines assembled from primitives such as Keccak, Feistel, SPECK and Threefish and stored Base16-encoded in the PE's .reloc section, so no two samples share an identical routine. Execution uses a variant of process ghosting: a temporary file is marked for deletion, then mapped as a PE image section (NtCreateSection with SEC_IMAGE) before the delete completes, leaving a running process whose backing image is never scannable on disk. Cruciferra hardens that trick with two anti-EDR steps, patching ZwQueryVirtualMemory so endpoint tools misread mapped memory, and neutering NtManageHotPatch to defeat image-integrity validation, alongside Import Address Table unhooking and indirect syscalls: per Proofpoint, "the malware reads a clean copy of ntdll.dll on disk and stores all stub pointers in a global structure for later usage." For EDR/AV termination it loads a legitimate-but-vulnerable signed driver (Proofpoint names GoFlyDrv.sys among the alternates) and issues control codes to kill security processes, classic BYOVD.

Attribution matters here: "Proofpoint observed four campaigns attributed to Chinese-speaking cybercrime actor TA4922 using Cruciferra to ultimately deliver AsyncRAT," behind landing pages mimicking government tax portals, against finance, healthcare and government targets.

the malware reads a clean copy of ntdll.dll on disk and stores all stub pointers in a global structure for later usage.

Proofpoint observed four campaigns attributed to Chinese-speaking cybercrime actor TA4922 using Cruciferra to ultimately deliver AsyncRAT.

Proofpoint Threat Insight 2026-07-20
threat21 Jul 04:41Zmulti-sourceOpen finding →

2026-06-18 · view entry permalink →

NOTABLE

China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network

Chinese police arrested 67 suspects across five provinces in a June 2026 operation against Silver Fox (also tracked as Void Arachne, UTG-Q-1000 and TA4922) assessed as one of the most active crimeware operations targeting Chinese-speaking users (Risky Biz News, 2026-06-17). The arrests reportedly span the full criminal supply chain: the primary developer/seller of the Silver Fox (Winos) trojan, a variant developer, phishing-site operators, and fake-app download-site operators, with secondary RATs including ValleyRAT used for credential theft. A CNCERT/CC security alert issued on 2026-05-22 preceded the operation (CNCERT/CC, 2026-05-22).

threat18 Jun 05:10Zmulti-sourceOpen finding →

Earlier coverage (1)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats4

Source distribution

  • proofpoint.com2 (29%)
  • bleepingcomputer.com1 (14%)
  • cert.org.cn1 (14%)
  • infosecurity-magazine.com1 (14%)
  • news.risky.biz1 (14%)
  • thehackernews.com1 (14%)