Chinese hackers use new Atlas RAT malware in European cyberattacks
Proofpoint says TA4922 has shifted into Europe with new malware and phishing lures, including Atlas RAT. The group is focused on fraud, theft, and access sales, but its tools could also support surveillance.
Intelligence analysis by GPT-5.4 Mini

Proofpoint says a Chinese-speaking cybercrime group tracked as TA4922 has broadened its reach from East Asia into Europe, using localized lures and several malware families. The campaign mix suggests a fast-moving crew built for theft, access, and possibly surveillance.
A hacker group has been sending fake work and government messages to trick people in Europe. Their new bad software can spy, steal files, and even turn on cameras or microphones, like a thief that can also watch from inside the house.
Analysis
What changed
Proofpoint says TA4922, a Chinese-speaking threat actor, has expanded from earlier East Asia activity into Europe, with recent campaigns aimed at organizations in Germany, Italy, the United Kingdom, and South Africa. The group is assessed as financially motivated and linked to fraud, data theft, and the sale of access.
Tools and tactics
The cluster uses localized phishing lures that imitate payroll notices, tax audits, VAT filings, government compliance notices, invoices, and HR messages. It also reaches out through WhatsApp, LINE, and Microsoft Teams to pressure or engage targets.
Proofpoint says the group has increased its pace since March and has shown unusual variety since April. The company notes that TA4922 now runs more unique campaigns than any other cybercrime actor it tracks. That tempo matters because it gives defenders less time to spot one pattern before the group shifts to another.
Malware observed
Researchers say TA4922 is using Atlas RAT, a newly identified remote access trojan with system reconnaissance, file theft, plugin and payload downloads, keylogging, screenshot capture, audio and webcam recording, and reboot/shutdown commands. The malware also checks for signs of analysis and sandboxing, including Defender Application Guard-related markers and specific services or UUID patterns.
Proofpoint also identified RomulusLoader, which uses process hollowing, shellcode injection, and direct execution to launch additional payloads, including AnyDesk and SyncFuture. A separate Python-based loader, SilentRunLoader, steals Chrome credentials, cookies, and browsing data. The group has also deployed Winos4.0, which Proofpoint tracks as ValleyRAT.
Why the report stands out
Proofpoint says the code it saw may have been accelerated with large language models, based on placeholder values, comments, and patterns that resemble AI-generated code. The report also includes indicators of compromise for the malware and command-and-control infrastructure, which gives defenders concrete material to hunt with.
Key points
- Proofpoint says TA4922 has expanded from East Asia into Europe, with targets in Germany, Italy, the United Kingdom, and South Africa.
- The group uses localized phishing lures that imitate payroll, tax, VAT, compliance, invoice, and HR messages.
- Atlas RAT adds remote access, file theft, keylogging, screenshots, audio and webcam recording, and reboot or shutdown commands.
- Researchers also found RomulusLoader, SilentRunLoader, and deployments of Winos4.0/ValleyRAT.
- Proofpoint says the malware and campaign patterns could support surveillance as well as financially motivated crime.
- The report includes indicators of compromise for the malware and command-and-control infrastructure.
Proofpoint says it published indicators of compromise and command-and-control details, which can help defenders hunt for the activity and block related infrastructure. The detailed breakdown of lures and malware behavior may also help security teams recognize similar campaigns faster.
The group is moving quickly, using many lures and multiple malware families, which makes it harder to build reliable detections. Because Atlas RAT includes surveillance features, the activity could support not just theft but also broader intelligence gathering if it spreads or gets reused.



