Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Home/Threats/Proofpoint Warns of Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT Deployments
Threats

Proofpoint Warns of Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT Deployments

Key Takeaways A sophisticated cybercrime group, TA4922, is actively deploying a range of advanced malware, including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. The group targets...

Jennifer sherman
Jennifer sherman
June 4, 2026 5 Min Read
56 0

Key Takeaways

  • A sophisticated cybercrime group, TA4922, is actively deploying a range of advanced malware, including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT.
  • The group targets organizations across Japan, the UK, Germany, and Southeast Asia with financially motivated campaigns.
  • TA4922 utilizes highly convincing, localized social engineering tactics via email, often impersonating HR or tax authorities.
  • The threat actor is noted for its rapid development of new malware, potentially leveraging AI coding tools, and blending malicious activity with legitimate tools and cloud services to evade detection.

Cybercrime Group TA4922 Escalates Global Malware Deployment

Proofpoint has issued a stern warning regarding the escalating activities of TA4922, a sophisticated cybercrime group now deploying a diverse array of advanced malware families. Recent intelligence from Proofpoint details the active use of Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT across multiple regions, signaling a significant threat to global organizations. This activity is comprehensively documented in a detailed threat report.

Table Of Content

  • Key Takeaways
  • Cybercrime Group TA4922 Escalates Global Malware Deployment
  • Sophisticated Social Engineering and Rapid Malware Development
  • TA4922’s Malware Arsenal and Campaign Details
  • What You Should Do

The campaigns orchestrated by TA4922 are driven by financial gain and exhibit a level of strategic planning that distinguishes the group from typical criminal actors. What began as a regionally focused operation has rapidly expanded, establishing TA4922 as an increasingly global threat.

Sophisticated Social Engineering and Rapid Malware Development

A key element of TA4922’s modus operandi is its highly effective social engineering. The group crafts bespoke email lures, meticulously localized and designed to appear as legitimate communications from HR departments, tax authorities, or payroll teams. These convincing messages trick unsuspecting employees into clicking malicious links or opening infected attachments, leading to the silent installation of malware.

According to analysts at Proofpoint, TA4922 is a highly adaptive and sophisticated actor, continuously evolving its malware arsenal. The group’s primary objectives include data theft, financial fraud, and establishing persistent access within victim environments. Proofpoint’s threat intelligence indicates that TA4922 currently conducts more unique campaigns than any other tracked cybercrime actor.

TA4922 first emerged on Proofpoint’s radar in spring 2025, initially concentrating its efforts on East Asia. By early 2026, the group had significantly broadened its operational scope to include targets in Europe and South Africa. A characteristic of TA4922’s attacks is the strategic integration of malicious activities with legitimate tools and trusted cloud hosting services, complicating detection efforts.

One particularly concerning aspect of TA4922’s capabilities is its rapid malware development cycle. Proofpoint assesses with high confidence that the group likely leverages AI coding tools to accelerate the creation of new Python-based malware. Evidence supporting this includes unchanged placeholder values, such as “your_secret_key_here,” found within SilentRunLoader’s code, suggesting minimal review of auto-generated components. This accelerated development pace forces defenders into a constant reactive state, chasing new malware variants.

TA4922’s Malware Arsenal and Campaign Details

Between March and April 2026, TA4922 executed several distinct campaigns, each deploying different malware strains.

  • Atlas RAT Campaigns: In early March, the group targeted Japanese organizations with HR-themed emails disguised as salary adjustment notices. These emails contained ZIP files hosted on GoFile, which, upon execution, performed DLL sideloading to deliver Atlas RAT. This RAT then established a command-and-control (C2) connection to 206.238.115.58 over port 886. A subsequent Atlas RAT campaign in April used similar HR lures, with filenames like “Paperwork.zip,” to target organizations in the UK and Germany. Atlas RAT is a comprehensive backdoor capable of keylogging, screen capture, webcam recording, file management, and remote command execution. It incorporates anti-sandbox checks and uses ChaCha encryption for C2 communication.
  • RomulusLoader Deployments: RomulusLoader first appeared in late March, targeting Japanese entities via files hosted on LimeWire. In mid-April, TA4922 utilized RomulusLoader to push legitimate remote monitoring tools such as AnyDesk and SyncFuture, deliberately blending into normal network traffic to avoid detection. RomulusLoader’s C2 infrastructure has been observed communicating over port 1234.
  • SilentRunLoader Attacks: UK targets were subjected to SilentRunLoader via fraudulent tax authority emails. This malware is designed to steal Chrome credentials and exfiltrate them to an actor-controlled server. Unchanged placeholder values in its code suggest rapid development, potentially with AI assistance.
  • ValleyRAT Integration: ValleyRAT, built on the Winos4.0 framework, further enhances TA4922’s capabilities by adding DDoS support and the ability to download additional modules on demand.

Collectively, these sophisticated tools grant TA4922 deep and persistent access to compromised systems, enabling a wide range of malicious activities.

What You Should Do

Organizations must take immediate action to mitigate their exposure to TA4922 and similar advanced threats. Proofpoint recommends several critical steps for defenders:

  • Enforce Application Allowlisting: Implement strict application allowlisting policies on trusted directories to prevent unauthorized executables from running.
  • Monitor and Restrict Execution: Actively monitor or prevent the execution of files from temporary folders (e.g., %TEMP%, %APPDATA%), which are frequently abused by malware like RomulusLoader. Additionally, watch for executables written to root directories.
  • Network Traffic Monitoring: Flag and investigate traffic to unusual ports, particularly port 1234, known to be used by RomulusLoader’s C2 infrastructure.
  • Implement Least Privilege: Apply the principle of least privilege across all user accounts to minimize the potential damage an attacker can inflict if a system is compromised.
  • Enhance Social Engineering Awareness: Since TA4922 is known to transition victims from email to messaging platforms like WhatsApp and Microsoft Teams, provide comprehensive employee training on recognizing and reporting social engineering attempts across all communication channels before a full compromise occurs.

Indicators of Compromise (IoCs):

Type Indicator Description
IP Address 206.238.115.58 Atlas RAT C2 (Campaign 1, March 2026)
IP Address 154.211.86.110 Atlas RAT C2 (Campaigns 2 and 3, April 2026)
IP Address 43.156.77.97 RomulusLoader C2 (March 2026)
IP Address 103.214.172.33 RomulusLoader First-stage C2 (April 2026)
IP Address 18.139.83.110 SilentRunLoader data exfiltration IP
Domain ws[.]ztts88[.]cyou SilentRunLoader C2 domain
URL https://ws.ztts88[.]cyou/file/cg[.]exe SilentRunLoader payload download URL
URL https://ws.ztts88[.]cyou/upload[.]php SilentRunLoader data exfiltration URL
URL https://nwphotoblog[.]com URL used in RomulusLoader/SyncFuture campaign
Domain aeya388[.]club ValleyRAT (Winos4.0) C2 domain
SHA256 a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295 ZIP archive delivering Atlas RAT (March 2026)
SHA256 584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8 Atlas RAT DLL (libcef.dll, March 2026)
SHA256 66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d ZIP archive (Paperwork.zip) delivering Atlas RAT
SHA256 4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9d ZIP archive (HR (2).zip) delivering Atlas RAT
SHA256 a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dad Atlas RAT DLL (libcef.dll, April 2026)
SHA256 40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5 RAR archive delivering RomulusLoader
SHA256 8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0 RomulusLoader DLL (vulkan-1.dll)
SHA256 3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d RomulusLoader component (vulkan-1.bin)
SHA256 314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279ef RomulusLoader/SyncFuture ZIP archive
SHA256 2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15d RomulusLoader/SyncFuture executable
SHA256 0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8 RomulusLoader/SyncFuture DLL
SHA256 e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088c SilentRunLoader executable (March 2026)
SHA256 de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2 SilentRunLoader ZIP (April 2026)
SHA256 9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73 SilentRunLoader executable (April 2026)
File Name vulkan-1.dll RomulusLoader malicious DLL masquerading as Vulkan component
File Name libcef.dll Atlas RAT malicious DLL used in multiple campaigns
File Name cg.exe SilentRunLoader next-stage compiled Python payload

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Fake ChatGPT Site Spreads Malware Through Google Ads

Next Post

Phishing Attacks Shift to Infostealer Malware Over Fake Login Pages

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Critical CUPS Vulnerability (CVE-2023-4586) Lets Attackers Gain Root Privileges
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us