Threat Reports

Read other reports

DNS Investigation: Threat Actor TA4922 Goes Global

Proofpoint uncovered1 the global expansion of TA4922, a suspected Chinese-speaking cybercrime group that rapidly rotates malware—including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0)—and used localized HR-, tax-, and invoice-themed lures to deliver malware, credential phishing, and fraud schemes across Asia, Europe, and Africa.

The original analysis publicized seven network IoCs. Aided by the WhoisXML API MCP Server2, we investigated eight IoCs—one subdomain, two domains, and five IP addresses—after extracting the apex domain from the subdomain IoC.

96

Original IoCs Analyzed

Domain and IP indicators from the reported campaign

Key Findings

348

Email-connected domains

186

Additional IP addresses

728

String-connected domains

320

Malicious artifacts

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Domain IoC legitimacy check
  • Client traffic and typosquatting analysis
  • Domain IoC WHOIS and DNS history analysis
  • Email-connected domain discovery
  • IP and IP-connected domain discovery
  • String-connected domain discovery

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global
  • [2] https://main.whoisxmlapi.com/ai/mcp-server

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.