Threadlinqs IntelligenceStart free

Threat actorCNTracked since 2026-06

TA4922

Also known as:Silver FoxVoid Arachne

As of 2026-08-29, TA4922 is a CN-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as Silver Fox, Void Arachne. ATT&CK coverage spans 29 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1056 (Input Capture), T1082 (System Information Discovery).

Tracked threats
22 high
First seen
2026-06-04
Last seen
2026-08-29
ATT&CK techniques
29across 2 of 2 threats
Related CVEs
0None referenced
Attribution
CNNation or origin
Nation: CN · 2 tracked threat(s) · Categories: MALWARE

Activity timeline

TA4922 appears in 2 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

29 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (6), Collection (5), Command and Control (5), Discovery (3), Credential Access (2), Execution (2)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1056 Input Capture — Collectionobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1113 Screen Capture — Collectionobserved in 2 of 2 tracked threats
  • T1125 Video Capture — Collectionobserved in 2 of 2 tracked threats
  • T1204 User Execution — Executionobserved in 2 of 2 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 2 of 2 tracked threats
  • T1566 Phishing — Initial Accessobserved in 2 of 2 tracked threats
  • T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats
  • T1055 Process Injection — Privilege Escalationobserved in 1 of 2 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 1 of 2 tracked threats

Tracked threats