DNS Investigation: Threat Actor TA4922 Goes Global

Proofpoint uncovered1 the global expansion of TA4922, a suspected Chinese-speaking cybercrime group that rapidly rotates malware—including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0)—and used localized HR-, tax-, and invoice-themed lures to deliver malware, credential phishing, and fraud schemes across Asia, Europe, and Africa.

The original analysis publicized seven network IoCs. Aided by the WhoisXML API MCP Server2, we investigated eight IoCs—one subdomain, two domains, and five IP addresses—after extracting the apex domain from the subdomain IoC.

8

Original IoCs Analyzed

Domains, IPs, subdomains, and related indicators

Key Findings

2,779

Email-connected domains

1

Additional IP address

37

IP-connected domains

58

Malicious Articfacts

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Subdomain IoCs malicious infrastructure check
  • Domain IoCs WHOIS and DNS history analysis
  • IP IoCs geolocation and traffic analysis
  • Email-connected domain discovery
  • IP-connected domain discovery
  • Malicious artifact confirmation

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started