Chinese Cybercrime Group TA4922 Expands Campaigns Targeting Global Organizations
A Chinese-speaking cybercrime group known as TA4922 has been intensifying its activities, targeting organizations across various regions including Japan, the UK, Germany, and South Africa. According to Proofpoint, the group employs social engineering tactics and distributes multiple malware families, focusing on credential phishing and fraud schemes. TA4922's campaigns are financially motivated, aiming to gain remote access to victim organizations for data theft and fraud. The group uses HR, payroll tax, and invoicing themes to lure victims into downloading malicious payloads or sharing credentials. Recently, TA4922 has expanded its operations to include European organizations, utilizing tools like RomulusLoader and SilentRunLoader to exfiltrate sensitive information.