# Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion)

> TA4922, a suspected Chinese-speaking, financially-motivated cybercrime group, has expanded from East Asia into the UK, Germany, Italy, and South Africa. Campaigns deliver the new Atlas RAT (recon, keylogging, screenshot, audio/webcam capture, file theft) via DLL sideloading, alongside RomulusLoader (RC4-encrypted C loader that injects into svchost.exe/dllhost.exe to stage RMM tools) and the Python-based SilentRunLoader Chrome stealer. Proofpoint assesses with high confidence the group is using LLMs to accelerate malware development.

- **Published:** 2026-06-04T00:00:00Z
- **Last reviewed:** 2026-06-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0680
- **ID:** TL-2026-0680
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** TA4922 (China)
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

TA4922 is a high-tempo, financially-motivated threat actor operating from East Asia and assessed as Chinese-speaking, with objectives spanning data theft, fraud, and the resale of network access. Historically focused on Japan, Taiwan, Korea, Singapore, and India, the group expanded in 2026 to target organizations in the United Kingdom, Germany, Italy, and South Africa. Proofpoint published primary analysis on 2026-06-03 (corroborated same day by BleepingComputer) documenting three previously undocumented malware families and continued use of Winos4.0/ValleyRAT.

INITIAL ACCESS: TA4922 relies on spear-phishing with heavily localized lures — payroll/salary adjustment notices (e.g. Japanese '【給与調整のお知らせ】.zip'), tax and VAT themes (UK HMRC, Munich Finanzamt audit impersonation), HR/benefits, invoices, and government compliance notifications. Payloads are staged on third-party file hosts (GoFile, LimeWire, MediaFire) behind URL shorteners (srt.tw), and victims are frequently engaged out-of-band over WhatsApp, LINE, and Microsoft Teams. Delivery archives (ZIP/RAR) pair a legitimate signed EXE with a malicious DLL for sideloading; RomulusLoader abuses Vulkan Loader components.

ATLAS RAT: A modular backdoor providing system reconnaissance, targeted file theft, plugin/payload download, keylogging, clipboard capture, screenshot capture, and audio/webcam recording, plus system shutdown/reboot. Atlas RAT transmits collected system information to its C2 using ChaCha encryption and has been observed performing DLL injection into WeChat.exe. Before executing, it runs extensive anti-analysis checks: WDAGUtilityAccount username and Windows Defender Application Guard registry keys, the CExecSvc container service, the 'mshome' DNS suffix, the 'vmsmb' Hyper-V device, and Windows UUID activation status. If any check indicates a hostile/sandbox environment, the malware self-terminates.

ROMULUSLOADER: A C-language loader featuring a custom PE loader with section mapping and relocation processing, dynamic API resolution via PEB/TEB walking with ROR13 hashing, and RC4 decryption of an embedded payload (XOR + ZLib used for additional payload delivery/decompression). It executes payloads through process hollowing, shellcode injection, and direct execution, injecting worker code into svchost.exe and dllhost.exe. Operationally it stages legitimate Remote Monitoring & Management tooling — AnyDesk and the Chinese RMM product SyncFuture — to establish durable hands-on-keyboard access, notably against German targets.

SILENTRUNLOADER: A Python-based loader/stealer that silently downloads and executes a follow-on payload, then separately exfiltrates Google Chrome credentials, cookies, browsing data, and backup files via HTTP POST to /upload.php. It was used against UK and Southeast Asian organizations with government-service impersonation lures. SilentRunLoader contains an LLM-development artifact — the placeholder string 'your_secret_key_here' — supporting Proofpoint's high-confidence assessment that TA4922 is using LLMs to rapidly produce new Python-based malware.

ATTRIBUTION: Chinese-language metadata in samples, infrastructure tied to Chinese providers, and tradecraft overlaps with activity previously tracked as Silver Fox and Void Arachne underpin a Chinese-speaking, financially-motivated assessment. No CVE is associated; this is a malware/campaign threat warranting fresh behavioral detection coverage for DLL sideloading, RMM abuse, and Chrome data theft.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1555 Credentials from Password Stores
- T1056 Input Capture
- T1082 System Information Discovery
- T1113 Screen Capture
- T1123 Audio Capture
- T1125 Video Capture
- T1115 Clipboard Data
- T1573 Encrypted Channel
- T1219 Remote Access Tools
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [TA4922: The Suspected Chinese Crime Group is Going Global](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global)
- [Chinese hackers use new Atlas RAT malware in European cyberattacks](https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/)
- [MITRE ATT&CK — T1574.002 DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK — T1219 Remote Access Software](https://attack.mitre.org/techniques/T1219/)
- [MITRE ATT&CK — T1555.003 Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0680
