DNS Investigation: Threat Actor TA4922 Goes Global
Proofpoint uncovered1 the global expansion of TA4922, a suspected Chinese-speaking cybercrime group that rapidly rotates malware—including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0)—and used localized HR-, tax-, and invoice-themed lures to deliver malware, credential phishing, and fraud schemes across Asia, Europe, and Africa.
The original analysis publicized seven network IoCs. Aided by the WhoisXML API MCP Server2, we investigated eight IoCs—one subdomain, two domains, and five IP addresses—after extracting the apex domain from the subdomain IoC.
Original IoCs Analyzed
Domains, IPs, subdomains, and related indicators
Key Findings
Additional IP address
IP-connected domains
Malicious Articfacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Subdomain IoCs malicious infrastructure check
- Domain IoCs WHOIS and DNS history analysis
- IP IoCs geolocation and traffic analysis
- Email-connected domain discovery
- IP-connected domain discovery
- Malicious artifact confirmation
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global
- [2] https://main.whoisxmlapi.com/ai/mcp-server