China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
TA4922 has broadened phishing campaigns into the U.K., Germany, Italy, and South Africa, using loaders, RATs, and chat apps to steal data.
Intelligence analysis by GPT-5.4 Mini

Proofpoint says TA4922 is scaling beyond East Asia, mixing HR, tax, invoice, and benefits lures with loaders and remote access malware. The group is also shifting victims from email to chat apps to slip past enterprise controls.
It is like a thief who keeps changing costumes and knocking on office doors in different countries. Instead of only using email, the thief also tries chat apps to slip past guards and steal keys to the building.
Analysis
What changed
Proofpoint says the China-linked group TA4922 has expanded its phishing activity to organizations in the U.K., Germany, Italy, and South Africa. The group was previously tracked as a Chinese-speaking actor that mostly targeted East Asia, but the article says its recent campaigns have widened in scope while keeping a fast operational pace.
How it works
The campaigns use business- and HR-themed lures, along with tax, invoice, benefits, and compliance themes, to trick targets into opening malicious content. The payloads include known malware families such as ValleyRAT and Atlas RAT, plus newer tools the article names RomulusLoader and SilentRunLoader. The report says these tools are delivered through DLL side-loading and, in at least one case, a Python-based loader that steals Chrome data including stored credentials, cookies, and browsing history.
A notable tactic shift is the move away from email-only contact. TA4922 has tried to pull conversations into LINE, WhatsApp, and Microsoft Teams, which can help it bypass normal enterprise email defenses and continue the attack in channels that may be less monitored.
What Proofpoint thinks
Proofpoint assesses TA4922 as likely financially motivated, focusing on remote access that can support data theft, fraud, access resale, or persistent entry into victim environments. It also warns that some of the malware has surveillance potential, which could make the tooling useful to other threat actors as well.
The article's main point is that the group is not staying local or static. It is broadening its target list, changing lures, and swapping tools quickly enough that defenders need to watch for both phishing delivery and the follow-on malware behavior.
Key points
- Proofpoint says TA4922 has expanded phishing attacks beyond East Asia to the U.K., Germany, Italy, and South Africa.
- The group uses HR, business, tax, invoice, benefits, and compliance-themed lures to deliver malware and steal credentials.
- Observed payloads include ValleyRAT, Atlas RAT, RomulusLoader, and SilentRunLoader.
- Attackers are trying to move victims from email to LINE, WhatsApp, and Microsoft Teams to bypass enterprise controls.
- Proofpoint assesses the actor as financially motivated, with data theft, fraud, access resale, and persistence as likely goals.
If defenders respond quickly, the shift to chat apps could push companies to watch more than email and tighten controls around LINE, WhatsApp, and Teams. Better visibility into these new lures and loaders could help organizations spot the campaigns earlier and stop credential theft before access spreads.
The group is changing tools and targets quickly, so attacks may keep landing before security teams update filters and monitoring. Because the malware can steal credentials, cookies, and browsing data, stolen access may be reused for fraud, resale, or longer-term intrusion.



