Threat reportMalwareTL-2026-0680

Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion)

highACTIVE

Atlas RAT — Chinese-Speaking TA4922 Goes Global with (TL-2026-0680), also tracked as Atlas RAT, is a high-severity malware campaign, first published 2026-06-04. It is attributed to TA4922 (China) with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1027, T1041, T1055), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
1TA4922
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-0680

Threat ID
TL-2026-0680
Also known as
Atlas RAT, RomulusLoader, SilentRunLoader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
TA4922
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
finance, government, human-resources, tax-authority, enterprise
Target regions
United Kingdom, Germany, Italy, South Africa, Japan, Taiwan, Korea, Singapore, India
Detection rules
9
Indicators of compromise
24

Malware and tooling in Atlas RAT — Chinese-Speaking TA4922 Goes Global with

Malware and tooling: Atlas RAT, RomulusLoader, SilentRunLoader, AnyDesk, SyncFuture

How Atlas RAT — Chinese-Speaking TA4922 Goes Global with works

TA4922, a suspected Chinese-speaking, financially-motivated cybercrime group, has expanded from East Asia into the UK, Germany, Italy, and South Africa. Campaigns deliver the new Atlas RAT (recon, keylogging, screenshot, audio/webcam capture, file theft) via DLL sideloading, alongside RomulusLoader (RC4-encrypted C loader that injects into svchost.exe/dllhost.exe to stage RMM tools) and the Python-based SilentRunLoader Chrome stealer. Proofpoint assesses with high confidence the group is using LLMs to accelerate malware development.

TA4922 is a high-tempo, financially-motivated threat actor operating from East Asia and assessed as Chinese-speaking, with objectives spanning data theft, fraud, and the resale of network access. Historically focused on Japan, Taiwan, Korea, Singapore, and India, the group expanded in 2026 to target organizations in the United Kingdom, Germany, Italy, and South Africa. Proofpoint published primary analysis on 2026-06-03 (corroborated same day by BleepingComputer) documenting three previously undocumented malware families and continued use of Winos4.0/ValleyRAT.

INITIAL ACCESS: TA4922 relies on spear-phishing with heavily localized lures — payroll/salary adjustment notices (e.g. Japanese '【給与調整のお知らせ】.zip'), tax and VAT themes (UK HMRC, Munich Finanzamt audit impersonation), HR/benefits, invoices, and government compliance notifications. Payloads are staged on third-party file hosts (GoFile, LimeWire, MediaFire) behind URL shorteners (srt.tw), and victims are frequently engaged out-of-band over WhatsApp, LINE, and Microsoft Teams. Delivery archives (ZIP/RAR) pair a legitimate signed EXE with a malicious DLL for sideloading; RomulusLoader abuses Vulkan Loader components.

ATLAS RAT: A modular backdoor providing system reconnaissance, targeted file theft, plugin/payload download, keylogging, clipboard capture, screenshot capture, and audio/webcam recording, plus system shutdown/reboot. Atlas RAT transmits collected system information to its C2 using ChaCha encryption and has been observed performing DLL injection into WeChat.exe. Before executing, it runs extensive anti-analysis checks: WDAGUtilityAccount username and Windows Defender Application Guard registry keys, the CExecSvc container service, the 'mshome' DNS suffix, the 'vmsmb' Hyper-V device, and Windows UUID activation status. If any check indicates a hostile/sandbox environment, the malware self-terminates.

ROMULUSLOADER: A C-language loader featuring a custom PE loader with section mapping and relocation processing, dynamic API resolution via PEB/TEB walking with ROR13 hashing, and RC4 decryption of an embedded payload (XOR + ZLib used for additional payload delivery/decompression). It executes payloads through process hollowing, shellcode injection, and direct execution, injecting worker code into svchost.exe and dllhost.exe. Operationally it stages legitimate Remote Monitoring & Management tooling — AnyDesk and the Chinese RMM product SyncFuture — to establish durable hands-on-keyboard access, notably against German targets.

SILENTRUNLOADER: A Python-based loader/stealer that silently downloads and executes a follow-on payload, then separately exfiltrates Google Chrome credentials, cookies, browsing data, and backup files via HTTP POST to /upload.php. It was used against UK and Southeast Asian organizations with government-service impersonation lures. SilentRunLoader contains an LLM-development artifact — the placeholder string 'your_secret_key_here' — supporting Proofpoint's high-confidence assessment that TA4922 is using LLMs to rapidly produce new Python-based malware.

ATTRIBUTION: Chinese-language metadata in samples, infrastructure tied to Chinese providers, and tradecraft overlaps with activity previously tracked as Silver Fox and Void Arachne underpin a Chinese-speaking, financially-motivated assessment. No CVE is associated; this is a malware/campaign threat warranting fresh behavioral detection coverage for DLL sideloading, RMM abuse, and Chrome data theft.

MITRE ATT&CK techniques used in TL-2026-0680

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Privilege Escalation

T1055 Process Injection

Credential Access

T1056 Input Capture; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1082 System Information Discovery

Command and Control

T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture

Initial Access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

Affected products and versions in Atlas RAT — Chinese-Speaking TA4922 Goes Global with

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server
  • Google — Chrome
    Vulnerable versions: all (credential/cookie theft target)

Remediation for Atlas RAT — Chinese-Speaking TA4922 Goes Global with

Immediate actions

  • Block C2 IPs 206.238.115.58, 154.211.86.110, 43.156.77.97, 103.214.172.33, 18.139.83.110 and domains ws.ztts88.cyou, aeya388.club, nwphotoblog.com at the perimeter
  • Alert on outbound TCP to ports 886, 1234, 7880, 7881 to non-business destinations
  • Quarantine the listed Atlas RAT / RomulusLoader / SilentRunLoader sample hashes via EDR

Workarounds

  • Block inbound archives (ZIP/RAR) containing paired EXE+DLL at the email gateway
  • Block known third-party file hosts (GoFile, LimeWire, MediaFire) and URL shortener srt.tw where business needs permit

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL sideloading and injection into svchost.exe/dllhost.exe/WeChat.exe
  • Enforce application allow-listing to break legitimate-EXE + malicious-DLL pairings
  • Restrict and monitor unauthorized RMM software (AnyDesk, SyncFuture) via allow-listing

Timeline of Atlas RAT — Chinese-Speaking TA4922 Goes Global with

  • Proofpoint begins tracking TA4922 activity targeting East Asian organizations (Japan, Taiwan, Korea, Singapore, India).
  • SyncFuture RMM deployments first observed in TA4922 operations.
  • Atlas RAT Campaign 1 observed; first Atlas RAT ZIP and sideloaded DLL samples identified.
  • RomulusLoader first identified in the wild as a new C-language loader.
  • SilentRunLoader Python Chrome stealer EXE sample first identified.
  • Atlas RAT Campaign 2 observed amid sharply increased operational tempo.
  • Atlas RAT Campaign 3 observed; group demonstrates unprecedented operational diversity.
  • RomulusLoader observed staging legitimate RMM tools (AnyDesk, SyncFuture) against German targets.
  • Proofpoint publishes primary analysis; BleepingComputer corroborates Europe/Africa expansion (UK, Germany, Italy, South Africa).
  • Threadlinqs Intelligence publishes threat profile TL-2026-0680 with detection coverage.

Sources cited for Atlas RAT — Chinese-Speaking TA4922 Goes Global with

Detection coverage for TL-2026-0680

As of 2026-06-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0680 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats