Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion) — Threadlinqs Intelligence
As of 2026-06-04, Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion) is a high-severity malware threat attributed to TA4922 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0680 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: TA4922 · China · FINANCIAL
TA4922, a suspected Chinese-speaking, financially-motivated cybercrime group, has expanded from East Asia into the UK, Germany, Italy, and South Africa. Campaigns deliver the new Atlas RAT (recon,
TA4922 is a high-tempo, financially-motivated threat actor operating from East Asia and assessed as Chinese-speaking, with objectives spanning data theft, fraud, and the resale of network access. Historically focused on Japan, Taiwan, Korea, Singapore, and India, the group expanded in 2026 to target organizations in the United Kingdom, Germany, Italy, and South Africa. Proofpoint published primary analysis on 2026-06-03 (corroborated same day by BleepingComputer) documenting three previously undocumented malware families and continued use of Winos4.0/ValleyRAT.
INITIAL ACCESS: TA4922 relies on spear-phishing with heavily localized lures — payroll/salary adjustment notices (e.g. Japanese '【給与調整のお知らせ】.zip'), tax and VAT themes (UK HMRC, Munich Finanzamt audit impersonation), HR/benefits, invoices, and government compliance notifications. Payloads are staged on third-party file hosts (GoFile, LimeWire, MediaFire) behind URL shorteners (srt.tw), and victims are frequently engaged out-of-band over WhatsApp, LINE, and Microsoft Teams. Delivery archives (ZIP/RAR) pair a legitimate signed EXE with a malicious DLL for sideloading; RomulusLoader abuses Vulkan Loader components.
ATLAS RAT: A modular backdoor providing system reconnaissance, targeted file theft, plugin/payload download, keylogging, clipboard capture, screenshot capture, and audio/webcam recording, plus system shutdown/reboot. Atlas RAT transmits collected system information to its C2 using ChaCha encryption and has been observed performing DLL injection into WeChat.exe. Before executing, it runs extensive anti-analysis checks: WDAGUtilityAccount username and Windows Defender Application Guard registry keys, the CExecSvc container service, the 'mshome' DNS suffix, the 'vmsmb' Hyper-V device, and Windows UUID activation status. If any check indicates a hostile/sandbox environment, the malware self-terminates.
ROMULUSLOADER: A C-language loader featuring a custom PE loader with section mapping and relocation processing, dynamic API resolution via PEB/TEB walking with ROR13 hashing, and RC4 decryption of an embedded payload (XOR + ZLib used for additional payload delivery/decompression). It executes payloads through process hollowing, shellcode injection, and direct execution, injecting worker code into svchost.exe and dllhost.exe. Operationally it stages legitimate Remote Monitoring & Management tooling — AnyDesk and the Chinese RMM product SyncFuture — to establish durable hands-on-keyboard access, notably against German targets.
SILENTRUNLOADER: A Python-based loader/stealer that silently downloads and executes a follow-on payload, then separately exfiltrates Google Chrome credentials, cookies, browsing data, and backup files via HTTP POST to /upload.php. It was used against UK and Southeast Asian organizations with government-service impersonation lures. SilentRunLoader contains an LLM-development artifact — the placeholder string 'your_secret_key_here' — supporting Proofpoint's high-confidence assessment that TA4922 is using LLMs to rapidly produce new Python-based malware.
ATTRIBUTION: Chinese-language metadata in samples, infrastructure tied to Chinese providers, and tradecraft overlaps with activity previously tracked as Silver Fox and Void Arachne underpin a Chinese-speaking, financially-motivated assessment. No CVE is associated; this is a malware/campaign threat warranting fresh behavioral detection coverage for DLL sideloading, RMM abuse, and Chrome data theft.
Target sectors: finance, government, human-resources, tax-authority, enterprise
Target regions: United Kingdom, Germany, Italy, South Africa, Japan, Taiwan, Korea, Singapore, India
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1204, T1059, T1574, T1055, T1140, T1027, T1497, T1055