discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Chinese hackers use new Atlas RAT malware in European cyberattacks

Proofpoint says TA4922 has shifted into Europe with new malware and phishing lures, including Atlas RAT. The group is focused on fraud, theft, and access sales, but its tools could also support surveillance.

By Bill Toulas·Jun 3·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Chinese hackers use new Atlas RAT malware in European cyberattacks
Image: bleepingcomputer.com

Proofpoint says a Chinese-speaking cybercrime group tracked as TA4922 has broadened its reach from East Asia into Europe, using localized lures and several malware families. The campaign mix suggests a fast-moving crew built for theft, access, and possibly surveillance.

Why it matters

The story shows how quickly a financially motivated group can expand into new regions with tailored phishing and custom malware. It also matters because the malware set includes surveillance-capable features that could be reused beyond ordinary cybercrime.

A hacker group has been sending fake work and government messages to trick people in Europe. Their new bad software can spy, steal files, and even turn on cameras or microphones, like a thief that can also watch from inside the house.

Analysis

What changed

Proofpoint says TA4922, a Chinese-speaking threat actor, has expanded from earlier East Asia activity into Europe, with recent campaigns aimed at organizations in Germany, Italy, the United Kingdom, and South Africa. The group is assessed as financially motivated and linked to fraud, data theft, and the sale of access.

Tools and tactics

The cluster uses localized phishing lures that imitate payroll notices, tax audits, VAT filings, government compliance notices, invoices, and HR messages. It also reaches out through WhatsApp, LINE, and Microsoft Teams to pressure or engage targets.

Proofpoint says the group has increased its pace since March and has shown unusual variety since April. The company notes that TA4922 now runs more unique campaigns than any other cybercrime actor it tracks. That tempo matters because it gives defenders less time to spot one pattern before the group shifts to another.

Malware observed

Researchers say TA4922 is using Atlas RAT, a newly identified remote access trojan with system reconnaissance, file theft, plugin and payload downloads, keylogging, screenshot capture, audio and webcam recording, and reboot/shutdown commands. The malware also checks for signs of analysis and sandboxing, including Defender Application Guard-related markers and specific services or UUID patterns.

Proofpoint also identified RomulusLoader, which uses process hollowing, shellcode injection, and direct execution to launch additional payloads, including AnyDesk and SyncFuture. A separate Python-based loader, SilentRunLoader, steals Chrome credentials, cookies, and browsing data. The group has also deployed Winos4.0, which Proofpoint tracks as ValleyRAT.

Why the report stands out

Proofpoint says the code it saw may have been accelerated with large language models, based on placeholder values, comments, and patterns that resemble AI-generated code. The report also includes indicators of compromise for the malware and command-and-control infrastructure, which gives defenders concrete material to hunt with.

Key points

  • Proofpoint says TA4922 has expanded from East Asia into Europe, with targets in Germany, Italy, the United Kingdom, and South Africa.
  • The group uses localized phishing lures that imitate payroll, tax, VAT, compliance, invoice, and HR messages.
  • Atlas RAT adds remote access, file theft, keylogging, screenshots, audio and webcam recording, and reboot or shutdown commands.
  • Researchers also found RomulusLoader, SilentRunLoader, and deployments of Winos4.0/ValleyRAT.
  • Proofpoint says the malware and campaign patterns could support surveillance as well as financially motivated crime.
  • The report includes indicators of compromise for the malware and command-and-control infrastructure.
The Upside

Proofpoint says it published indicators of compromise and command-and-control details, which can help defenders hunt for the activity and block related infrastructure. The detailed breakdown of lures and malware behavior may also help security teams recognize similar campaigns faster.

The Downside

The group is moving quickly, using many lures and multiple malware families, which makes it harder to build reliable detections. Because Atlas RAT includes surveillance features, the activity could support not just theft but also broader intelligence gathering if it spreads or gets reused.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarephishingchinagermanyunited-kingdom

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 3, 2026

Source

bleepingcomputer.com

Share

Topics

securitymalwarephishingchinagermanyunited-kingdom

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…