LIVE NEWS
  • A handful of Americans pay for AI. Will you have to? : NPR
  • Lawmakers demand answers about $620M Pentagon loan to firm tied to Trump Jr.
  • Gas engine maker Innio set for Nasdaq debut after upsized $2.43 billion IPO
  • Army identifies soldier who died in training accident in Iraq
  • Stonehenge’s altar stone probably wasn’t transported by a glacier
  • Quiz: World Cup 2026 – player and team records, key statistics | World Cup 2026 News
  • Over $600M in Bitcoin Longs Liquidated As BTC Price Nears $60K
  • Chinese Cybercrime Group in Spotlight for Record Campaign Pace
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Chinese Cybercrime Group in Spotlight for Record Campaign Pace
Cybersecurity

Chinese Cybercrime Group in Spotlight for Record Campaign Pace

primereportsBy primereportsJune 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
Share
Facebook Twitter LinkedIn Pinterest Email


A Chinese-speaking cybercrime group tracked as TA4922 has been escalating activities and expanding to new geographies, Proofpoint reports.

Relying on social engineering, the hacking group has been continually updating its arsenal, distributing multiple malware families and also engaging in credential phishing and fraud schemes such as credit card theft.

While some of TA4922’s activities overlap with those of the threat actors tracked as Silver Fox and Void Arachne, the group does not appear to engage in espionage, unlike those clusters.

“The campaigns attributed to TA4922 align more closely with cybercriminal objectives despite the actor’s advanced tradecraft,” Proofpoint says.

The cybersecurity firm has been tracking TA4922 malicious email campaigns for over a year and believes that its focus is to obtain remote access to victim organizations for data theft, access resale, fraud, and other financially motivated activities.

Using HR, payroll tax, and invoicing themes, the hacking group attempts to lure victims into clicking on malicious links to download malicious payloads or unwittingly share their credentials.

Advertisement. Scroll to continue reading.

Historically, the cybercrime gang has sent hundreds to a few thousand messages per campaign, tailored to specific regions or business functions, targeting organizations in Japan, Taiwan, Korea, Singapore, and India.

Recently, the group also started targeting European organizations in the UK, Germany, and Italy, as well as entities in South Africa.

TA4922 was also seen launching credential-phishing and imposter campaigns, looking to shift communication from email to out-of-band channels, including messaging platforms such as LINE, WhatsApp, or Microsoft Teams.

“Once communication moves to those platforms, the actor is better positioned to extend social engineering, harvest contact information, or deliver malware beyond traditional email security visibility,” Proofpoint says.

In March, the threat actor used HR lures in campaigns targeting organizations in Japan with the Atlas RAT backdoor and the RomulusLoader malware loader.

In April, the group used HR lures and previous infrastructure in Atlas RAT attacks against organizations in the UK and Germany, but switched to customer service communications lures in another campaign.

Multiple April campaigns attributed to TA4922 relied on RomulusLoader to install legitimate Remote Monitoring and Management (RMM) tools, including AnyDesk and SyncFuture.

At the end of March, the group targeted UK organizations with the SilentRunLoader Python‑based loader and stealer to exfiltrate credentials, cookies, and browsing information from Google Chrome. In April, SilentRunLoader was used in attacks against entities in Southeast Asia and the UK.

According to Proofpoint, the cybercrime gang has also been observed using the ValleyRAT (Winos4.0) backdoor and other malware families in attacks.

“TA4922 currently conducts more unique campaigns than any other tracked cybercrime threat actor in Proofpoint threat data, demonstrating high operational tempo, a variety of lures, and multiple objectives. While the actor is assessed to be financially motivated, the capabilities of the malware include the potential for surveillance which could be used by or sold to espionage groups,” Proofpoint notes.

Related: Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

Related: Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

Related: Alleged Chinese State Hacker Extradited to US

Related: Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHPE Catches Its First GenAI Wave With Enterprises, Sovereigns, And Neoclouds
Next Article Over $600M in Bitcoin Longs Liquidated As BTC Price Nears $60K
primereports
  • Website

Related Posts

Cybersecurity

Microsoft responds to security challenges facing code, AI agents, and models

June 3, 2026
Cybersecurity

DOD wants to integrate cyber in all operations, and integrate security into AI

June 3, 2026
Cybersecurity

Trump Signs Order Inviting Voluntary Review of Frontier AI Models

June 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • A handful of Americans pay for AI. Will you have to? : NPR
  • Lawmakers demand answers about $620M Pentagon loan to firm tied to Trump Jr.
  • Gas engine maker Innio set for Nasdaq debut after upsized $2.43 billion IPO
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.