Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Proofpoint uncovered1 the global expansion of TA4922, a suspected Chinese-speaking cybercrime group that rapidly rotates malware—including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0)—and used localized HR-, tax-, and invoice-themed lures to deliver malware, credential phishing, and fraud schemes across Asia, Europe, and Africa.
The original analysis publicized seven network IoCs. Aided by the WhoisXML API MCP Server2, we investigated eight IoCs—one subdomain, two domains, and five IP addresses—after extracting the apex domain from the subdomain IoC.
Original IoCs Analyzed
Domain and IP indicators from the reported campaign
Key Findings
Email-connected domains
Additional IP addresses
String-connected domains
Malicious artifacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Domain IoC legitimacy check
- Client traffic and typosquatting analysis
- Domain IoC WHOIS and DNS history analysis
- Email-connected domain discovery
- IP and IP-connected domain discovery
- String-connected domain discovery
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global
- [2] https://main.whoisxmlapi.com/ai/mcp-server