Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Chinese Cybercrime Group in Spotlight for Record Campaign Pace

Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.

China APT

A Chinese-speaking cybercrime group tracked as TA4922 has been escalating activities and expanding to new geographies, Proofpoint reports.

Relying on social engineering, the hacking group has been continually updating its arsenal, distributing multiple malware families and also engaging in credential phishing and fraud schemes such as credit card theft.

While some of TA4922’s activities overlap with those of the threat actors tracked as Silver Fox and Void Arachne, the group does not appear to engage in espionage, unlike those clusters.

“The campaigns attributed to TA4922 align more closely with cybercriminal objectives despite the actor’s advanced tradecraft,” Proofpoint says.

The cybersecurity firm has been tracking TA4922 malicious email campaigns for over a year and believes that its focus is to obtain remote access to victim organizations for data theft, access resale, fraud, and other financially motivated activities.

Using HR, payroll tax, and invoicing themes, the hacking group attempts to lure victims into clicking on malicious links to download malicious payloads or unwittingly share their credentials.

Advertisement. Scroll to continue reading.

Historically, the cybercrime gang has sent hundreds to a few thousand messages per campaign, tailored to specific regions or business functions, targeting organizations in Japan, Taiwan, Korea, Singapore, and India.

Recently, the group also started targeting European organizations in the UK, Germany, and Italy, as well as entities in South Africa.

TA4922 was also seen launching credential-phishing and imposter campaigns, looking to shift communication from email to out-of-band channels, including messaging platforms such as LINE, WhatsApp, or Microsoft Teams.

“Once communication moves to those platforms, the actor is better positioned to extend social engineering, harvest contact information, or deliver malware beyond traditional email security visibility,” Proofpoint says.

In March, the threat actor used HR lures in campaigns targeting organizations in Japan with the Atlas RAT backdoor and the RomulusLoader malware loader.

In April, the group used HR lures and previous infrastructure in Atlas RAT attacks against organizations in the UK and Germany, but switched to customer service communications lures in another campaign.

Multiple April campaigns attributed to TA4922 relied on RomulusLoader to install legitimate Remote Monitoring and Management (RMM) tools, including AnyDesk and SyncFuture.

At the end of March, the group targeted UK organizations with the SilentRunLoader Python‑based loader and stealer to exfiltrate credentials, cookies, and browsing information from Google Chrome. In April, SilentRunLoader was used in attacks against entities in Southeast Asia and the UK.

According to Proofpoint, the cybercrime gang has also been observed using the ValleyRAT (Winos4.0) backdoor and other malware families in attacks.

“TA4922 currently conducts more unique campaigns than any other tracked cybercrime threat actor in Proofpoint threat data, demonstrating high operational tempo, a variety of lures, and multiple objectives. While the actor is assessed to be financially motivated, the capabilities of the malware include the potential for surveillance which could be used by or sold to espionage groups,” Proofpoint notes.

Related: Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

Related: Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

Related: Alleged Chinese State Hacker Extradited to US

Related: Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.