
TA4922 has expanded phishing attacks to UK Germany Italy and South Africa. The group uses ValleyRAT Winos 4.0 Atlas RAT AtlasCross RAT RomulusLoader and SilentRunLoader. Attacks rely on HR and business-themed lures to deliver malware and steal credentials. The actors shift to LINE WhatsApp and Microsoft Teams to bypass enterprise security controls. Proofpoint identifies TA4922 as financially motivated with capabilities for surveillance and data theft.
Tap to vote and see what everyone thinks.
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
Summary by ByteBrief