Threat reportMalwareTL-2026-0680
Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion)
Atlas RAT — Chinese-Speaking TA4922 Goes Global with (TL-2026-0680), also tracked as Atlas RAT, is a high-severity malware campaign, first published 2026-06-04. It is attributed to TA4922 (China) with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1027, T1041, T1055), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 1TA4922
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-0680
- Threat ID
- TL-2026-0680
- Also known as
- Atlas RAT, RomulusLoader, SilentRunLoader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- TA4922
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- finance, government, human-resources, tax-authority, enterprise
- Target regions
- United Kingdom, Germany, Italy, South Africa, Japan, Taiwan, Korea, Singapore, India
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Atlas RAT — Chinese-Speaking TA4922 Goes Global with
Malware and tooling: Atlas RAT, RomulusLoader, SilentRunLoader, AnyDesk, SyncFuture
How Atlas RAT — Chinese-Speaking TA4922 Goes Global with works
TA4922, a suspected Chinese-speaking, financially-motivated cybercrime group, has expanded from East Asia into the UK, Germany, Italy, and South Africa. Campaigns deliver the new Atlas RAT (recon, keylogging, screenshot, audio/webcam capture, file theft) via DLL sideloading, alongside RomulusLoader (RC4-encrypted C loader that injects into svchost.exe/dllhost.exe to stage RMM tools) and the Python-based SilentRunLoader Chrome stealer. Proofpoint assesses with high confidence the group is using LLMs to accelerate malware development.
TA4922 is a high-tempo, financially-motivated threat actor operating from East Asia and assessed as Chinese-speaking, with objectives spanning data theft, fraud, and the resale of network access. Historically focused on Japan, Taiwan, Korea, Singapore, and India, the group expanded in 2026 to target organizations in the United Kingdom, Germany, Italy, and South Africa. Proofpoint published primary analysis on 2026-06-03 (corroborated same day by BleepingComputer) documenting three previously undocumented malware families and continued use of Winos4.0/ValleyRAT.
INITIAL ACCESS: TA4922 relies on spear-phishing with heavily localized lures — payroll/salary adjustment notices (e.g. Japanese '【給与調整のお知らせ】.zip'), tax and VAT themes (UK HMRC, Munich Finanzamt audit impersonation), HR/benefits, invoices, and government compliance notifications. Payloads are staged on third-party file hosts (GoFile, LimeWire, MediaFire) behind URL shorteners (srt.tw), and victims are frequently engaged out-of-band over WhatsApp, LINE, and Microsoft Teams. Delivery archives (ZIP/RAR) pair a legitimate signed EXE with a malicious DLL for sideloading; RomulusLoader abuses Vulkan Loader components.
ATLAS RAT: A modular backdoor providing system reconnaissance, targeted file theft, plugin/payload download, keylogging, clipboard capture, screenshot capture, and audio/webcam recording, plus system shutdown/reboot. Atlas RAT transmits collected system information to its C2 using ChaCha encryption and has been observed performing DLL injection into WeChat.exe. Before executing, it runs extensive anti-analysis checks: WDAGUtilityAccount username and Windows Defender Application Guard registry keys, the CExecSvc container service, the 'mshome' DNS suffix, the 'vmsmb' Hyper-V device, and Windows UUID activation status. If any check indicates a hostile/sandbox environment, the malware self-terminates.
ROMULUSLOADER: A C-language loader featuring a custom PE loader with section mapping and relocation processing, dynamic API resolution via PEB/TEB walking with ROR13 hashing, and RC4 decryption of an embedded payload (XOR + ZLib used for additional payload delivery/decompression). It executes payloads through process hollowing, shellcode injection, and direct execution, injecting worker code into svchost.exe and dllhost.exe. Operationally it stages legitimate Remote Monitoring & Management tooling — AnyDesk and the Chinese RMM product SyncFuture — to establish durable hands-on-keyboard access, notably against German targets.
SILENTRUNLOADER: A Python-based loader/stealer that silently downloads and executes a follow-on payload, then separately exfiltrates Google Chrome credentials, cookies, browsing data, and backup files via HTTP POST to /upload.php. It was used against UK and Southeast Asian organizations with government-service impersonation lures. SilentRunLoader contains an LLM-development artifact — the placeholder string 'your_secret_key_here' — supporting Proofpoint's high-confidence assessment that TA4922 is using LLMs to rapidly produce new Python-based malware.
ATTRIBUTION: Chinese-language metadata in samples, infrastructure tied to Chinese providers, and tradecraft overlaps with activity previously tracked as Silver Fox and Void Arachne underpin a Chinese-speaking, financially-motivated assessment. No CVE is associated; this is a malware/campaign threat warranting fresh behavioral detection coverage for DLL sideloading, RMM abuse, and Chrome data theft.
MITRE ATT&CK techniques used in TL-2026-0680
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Privilege Escalation
Credential Access
T1056 Input Capture; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
T1082 System Information Discovery
Command and Control
T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture
Initial Access
stealth
Affected products and versions in Atlas RAT — Chinese-Speaking TA4922 Goes Global with
Remediation for Atlas RAT — Chinese-Speaking TA4922 Goes Global with
Immediate actions
- Block C2 IPs 206.238.115.58, 154.211.86.110, 43.156.77.97, 103.214.172.33, 18.139.83.110 and domains ws.ztts88.cyou, aeya388.club, nwphotoblog.com at the perimeter
- Alert on outbound TCP to ports 886, 1234, 7880, 7881 to non-business destinations
- Quarantine the listed Atlas RAT / RomulusLoader / SilentRunLoader sample hashes via EDR
Workarounds
- Block inbound archives (ZIP/RAR) containing paired EXE+DLL at the email gateway
- Block known third-party file hosts (GoFile, LimeWire, MediaFire) and URL shortener srt.tw where business needs permit
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading and injection into svchost.exe/dllhost.exe/WeChat.exe
- Enforce application allow-listing to break legitimate-EXE + malicious-DLL pairings
- Restrict and monitor unauthorized RMM software (AnyDesk, SyncFuture) via allow-listing
Timeline of Atlas RAT — Chinese-Speaking TA4922 Goes Global with
- Proofpoint begins tracking TA4922 activity targeting East Asian organizations (Japan, Taiwan, Korea, Singapore, India).
- SyncFuture RMM deployments first observed in TA4922 operations.
- Atlas RAT Campaign 1 observed; first Atlas RAT ZIP and sideloaded DLL samples identified.
- RomulusLoader first identified in the wild as a new C-language loader.
- SilentRunLoader Python Chrome stealer EXE sample first identified.
- Atlas RAT Campaign 2 observed amid sharply increased operational tempo.
- Atlas RAT Campaign 3 observed; group demonstrates unprecedented operational diversity.
- RomulusLoader observed staging legitimate RMM tools (AnyDesk, SyncFuture) against German targets.
- Proofpoint publishes primary analysis; BleepingComputer corroborates Europe/Africa expansion (UK, Germany, Italy, South Africa).
- Threadlinqs Intelligence publishes threat profile TL-2026-0680 with detection coverage.
Sources cited for Atlas RAT — Chinese-Speaking TA4922 Goes Global with
Detection coverage for TL-2026-0680
As of 2026-06-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0680 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.