Proofpoint Warns of Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT Deployments
Key Takeaways A sophisticated cybercrime group, TA4922, is actively deploying a range of advanced malware, including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. The group targets...
Key Takeaways
- A sophisticated cybercrime group, TA4922, is actively deploying a range of advanced malware, including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT.
- The group targets organizations across Japan, the UK, Germany, and Southeast Asia with financially motivated campaigns.
- TA4922 utilizes highly convincing, localized social engineering tactics via email, often impersonating HR or tax authorities.
- The threat actor is noted for its rapid development of new malware, potentially leveraging AI coding tools, and blending malicious activity with legitimate tools and cloud services to evade detection.
Cybercrime Group TA4922 Escalates Global Malware Deployment
Proofpoint has issued a stern warning regarding the escalating activities of TA4922, a sophisticated cybercrime group now deploying a diverse array of advanced malware families. Recent intelligence from Proofpoint details the active use of Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT across multiple regions, signaling a significant threat to global organizations. This activity is comprehensively documented in a detailed threat report.
Table Of Content
The campaigns orchestrated by TA4922 are driven by financial gain and exhibit a level of strategic planning that distinguishes the group from typical criminal actors. What began as a regionally focused operation has rapidly expanded, establishing TA4922 as an increasingly global threat.
Sophisticated Social Engineering and Rapid Malware Development
A key element of TA4922’s modus operandi is its highly effective social engineering. The group crafts bespoke email lures, meticulously localized and designed to appear as legitimate communications from HR departments, tax authorities, or payroll teams. These convincing messages trick unsuspecting employees into clicking malicious links or opening infected attachments, leading to the silent installation of malware.
According to analysts at Proofpoint, TA4922 is a highly adaptive and sophisticated actor, continuously evolving its malware arsenal. The group’s primary objectives include data theft, financial fraud, and establishing persistent access within victim environments. Proofpoint’s threat intelligence indicates that TA4922 currently conducts more unique campaigns than any other tracked cybercrime actor.
TA4922 first emerged on Proofpoint’s radar in spring 2025, initially concentrating its efforts on East Asia. By early 2026, the group had significantly broadened its operational scope to include targets in Europe and South Africa. A characteristic of TA4922’s attacks is the strategic integration of malicious activities with legitimate tools and trusted cloud hosting services, complicating detection efforts.
One particularly concerning aspect of TA4922’s capabilities is its rapid malware development cycle. Proofpoint assesses with high confidence that the group likely leverages AI coding tools to accelerate the creation of new Python-based malware. Evidence supporting this includes unchanged placeholder values, such as “your_secret_key_here,” found within SilentRunLoader’s code, suggesting minimal review of auto-generated components. This accelerated development pace forces defenders into a constant reactive state, chasing new malware variants.
TA4922’s Malware Arsenal and Campaign Details
Between March and April 2026, TA4922 executed several distinct campaigns, each deploying different malware strains.
- Atlas RAT Campaigns: In early March, the group targeted Japanese organizations with HR-themed emails disguised as salary adjustment notices. These emails contained ZIP files hosted on GoFile, which, upon execution, performed DLL sideloading to deliver Atlas RAT. This RAT then established a command-and-control (C2) connection to 206.238.115.58 over port 886. A subsequent Atlas RAT campaign in April used similar HR lures, with filenames like “Paperwork.zip,” to target organizations in the UK and Germany. Atlas RAT is a comprehensive backdoor capable of keylogging, screen capture, webcam recording, file management, and remote command execution. It incorporates anti-sandbox checks and uses ChaCha encryption for C2 communication.
- RomulusLoader Deployments: RomulusLoader first appeared in late March, targeting Japanese entities via files hosted on LimeWire. In mid-April, TA4922 utilized RomulusLoader to push legitimate remote monitoring tools such as AnyDesk and SyncFuture, deliberately blending into normal network traffic to avoid detection. RomulusLoader’s C2 infrastructure has been observed communicating over port 1234.
- SilentRunLoader Attacks: UK targets were subjected to SilentRunLoader via fraudulent tax authority emails. This malware is designed to steal Chrome credentials and exfiltrate them to an actor-controlled server. Unchanged placeholder values in its code suggest rapid development, potentially with AI assistance.
- ValleyRAT Integration: ValleyRAT, built on the Winos4.0 framework, further enhances TA4922’s capabilities by adding DDoS support and the ability to download additional modules on demand.
Collectively, these sophisticated tools grant TA4922 deep and persistent access to compromised systems, enabling a wide range of malicious activities.
What You Should Do
Organizations must take immediate action to mitigate their exposure to TA4922 and similar advanced threats. Proofpoint recommends several critical steps for defenders:
- Enforce Application Allowlisting: Implement strict application allowlisting policies on trusted directories to prevent unauthorized executables from running.
- Monitor and Restrict Execution: Actively monitor or prevent the execution of files from temporary folders (e.g., %TEMP%, %APPDATA%), which are frequently abused by malware like RomulusLoader. Additionally, watch for executables written to root directories.
- Network Traffic Monitoring: Flag and investigate traffic to unusual ports, particularly port 1234, known to be used by RomulusLoader’s C2 infrastructure.
- Implement Least Privilege: Apply the principle of least privilege across all user accounts to minimize the potential damage an attacker can inflict if a system is compromised.
- Enhance Social Engineering Awareness: Since TA4922 is known to transition victims from email to messaging platforms like WhatsApp and Microsoft Teams, provide comprehensive employee training on recognizing and reporting social engineering attempts across all communication channels before a full compromise occurs.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| IP Address | 206.238.115.58 | Atlas RAT C2 (Campaign 1, March 2026) |
| IP Address | 154.211.86.110 | Atlas RAT C2 (Campaigns 2 and 3, April 2026) |
| IP Address | 43.156.77.97 | RomulusLoader C2 (March 2026) |
| IP Address | 103.214.172.33 | RomulusLoader First-stage C2 (April 2026) |
| IP Address | 18.139.83.110 | SilentRunLoader data exfiltration IP |
| Domain | ws[.]ztts88[.]cyou | SilentRunLoader C2 domain |
| URL | https://ws.ztts88[.]cyou/file/cg[.]exe | SilentRunLoader payload download URL |
| URL | https://ws.ztts88[.]cyou/upload[.]php | SilentRunLoader data exfiltration URL |
| URL | https://nwphotoblog[.]com | URL used in RomulusLoader/SyncFuture campaign |
| Domain | aeya388[.]club | ValleyRAT (Winos4.0) C2 domain |
| SHA256 | a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295 | ZIP archive delivering Atlas RAT (March 2026) |
| SHA256 | 584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8 | Atlas RAT DLL (libcef.dll, March 2026) |
| SHA256 | 66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60d | ZIP archive (Paperwork.zip) delivering Atlas RAT |
| SHA256 | 4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9d | ZIP archive (HR (2).zip) delivering Atlas RAT |
| SHA256 | a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dad | Atlas RAT DLL (libcef.dll, April 2026) |
| SHA256 | 40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5 | RAR archive delivering RomulusLoader |
| SHA256 | 8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0 | RomulusLoader DLL (vulkan-1.dll) |
| SHA256 | 3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2d | RomulusLoader component (vulkan-1.bin) |
| SHA256 | 314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279ef | RomulusLoader/SyncFuture ZIP archive |
| SHA256 | 2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15d | RomulusLoader/SyncFuture executable |
| SHA256 | 0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8 | RomulusLoader/SyncFuture DLL |
| SHA256 | e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088c | SilentRunLoader executable (March 2026) |
| SHA256 | de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2 | SilentRunLoader ZIP (April 2026) |
| SHA256 | 9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73 | SilentRunLoader executable (April 2026) |
| File Name | vulkan-1.dll | RomulusLoader malicious DLL masquerading as Vulkan component |
| File Name | libcef.dll | Atlas RAT malicious DLL used in multiple campaigns |
| File Name | cg.exe | SilentRunLoader next-stage compiled Python payload |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.