Utopia Tech
SecurityAI-assisted1 min read

China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

China-linked threat actor TA4922 has expanded its phishing campaign operations from initial targets to include organizations in the UK, Germany, Italy, and South Africa. The group demonstrates a rapid operational tempo and employs an evolving malware toolkit that includes ValleyRAT (Winos 4.0) and Atlas RAT (AtlasCross RAT) among other tools.

UT

Utopia Tech

June 4, 2026 · 1 min read

Share

A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a "rapid operational tempo" and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content