Chinese-speaking cybercrime group TA4922 expands operations to Europe and Africa (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- TA4922 expands targeting from East Asia to Europe (UK, DE, IT) and Africa (ZA).
- New malware: Atlas RAT, RomulusLoader, SilentRunLoader.
- AI (LLMs) used to rapidly build Python malware.
- Localized phishing lures and shift to messaging apps.
"Newly named Chinese-speaking group TA4922, financially motivated, has expanded from East Asia to Europe and Africa. It uses a rapidly changing malware arsenal including new backdoor Atlas RAT and leverages AI to quickly build Python malware. Proofpoint evidence shows the group attempts to move victims off email onto messaging platforms via localized phishing campaigns."
no comments yet.