TA4922
· Published 04/06/2026 10:38 · Modified 04/06/2026 10:38
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 04/06/2026 10:38
- Modified
- 04/06/2026 10:38
- Updated at
- 04/06/2026 10:38
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 23 attack patterns (mitre), 8 malware, 11 countries, 23 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
AlienVault Confidence 100 23 MITREs 8 Malwares 23 IOCs 23 Observables 1 APTPublished 03/06/2026 14:55 · Modified 04/06/2026 08:40 · threat-report
Attack patterns (MITRE) (23)
-
T1598 usesPhishing for Information
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1055 usesProcess Injection
-
T1566 usesPhishing
-
T1005 usesData from Local System
-
T1056.001 usesKeylogging
-
T1566.002 usesSpearphishing Link
-
T1055.003 usesThread Execution Hijacking
-
T1041 usesExfiltration Over C2 Channel
-
T1204.002 usesMalicious File
-
T1105 usesIngress Tool Transfer
-
T1055.001 usesDynamic-link Library Injection
-
T1566.001 usesSpearphishing Attachment
-
T1574.002 uses
-
T1113 usesScreen Capture
-
T1573.001 usesSymmetric Cryptography
-
T1055.012 usesProcess Hollowing
-
T1571 usesNon-Standard Port
-
T1204.001 usesMalicious Link
-
T1119 usesAutomated Collection
-
T1566.003 usesSpearphishing via Service
-
T1125 usesVideo Capture
-
T1027 usesObfuscated Files or Information
Malware (8)
-
SilentRunLoader usesFamilyPublished 03/06/2026 12:55 · Modified 03/06/2026 12:55
-
AnyDesk usesFamilyPublished 10/06/2026 11:58 · Modified 10/06/2026 11:58
-
HoldingHands usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 20:01 · Modified 21/12/2025 18:48
-
Winos4.0 usesFamilyPublished 03/06/2026 12:55 · Modified 03/06/2026 12:55
-
RomulusLoader usesFamilyPublished 03/06/2026 12:55 · Modified 03/06/2026 12:55
-
Atlas RAT usesFamilyPublished 03/06/2026 12:55 · Modified 03/06/2026 12:55
-
SyncFuture usesFamilyPublished 03/06/2026 12:55 · Modified 03/06/2026 12:55
-
ValleyRAT usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
Countries (11)
- Singapore targets
- South Africa targets
- Malaysia targets
- British Indian Ocean Territory targets
- Italy targets
- Indonesia targets
- Japan targets
- Germany targets
- Taiwan targets
- United Kingdom of Great Britain and Northern Ireland targets
- India targets
Indicators (23)
-
a75eab31d7ff06b6864960ad7e633be3f9730ff3d3873e4539c8f425fc632dadindicates -
4fcfa88fffacbce30bbe2136753c9ab5a4c092940d2406fd9d44d5118e745b9dindicates -
0857148fb0bc4aa7adf967ede2307bdb4fc427065d5b6a6db132688a5a8e1eb8indicates -
66a3836b9a17771bce2161f6b73cbc2494a91e49d6aa30d2d53711e8d10de60dindicates -
de82998ad5fcd63deae030803388e0fb4290d6223fda82368fd25b99b823f0d2indicates -
3119cf37b8267db8a2dcd11d9a83d5237d7ef1e42388e7c9afa2831b91da8a2dindicates -
https://ws.ztts88.cyou/upload.phpindicates -
9d0a55c545c4147956db2c2667c4ed931a2875309147548b1dfdd216228f5f73indicates -
8c9b6542f73c5c7fe455b52f5101314407da4f65ff48e7ebf6896605e607c8d0indicates -
a648db354820ea4d02940cb1702b35974513b7aae83f6dffaacaac4ba31f9295indicates -
nwphotoblog.comindicates -
40b41979b317406f8abc601677a3b93aaf6ef8ab8ac188b8f383735e388f13b5indicates -
314f4b59535d1b783e1c20c2be00f9e30f8ed27b2e21fad06a73b47ea43279efindicates -
https://ws.ztts88.cyou/file/cg.exeindicates -
e0a6a71c605d9a4076147e9537f82f79f1e1eccadc874595160aa4637ff4088cindicates -
112.121.183.202indicates -
584a9448dda46bd590d7a2f86228100d2ae6e0d6d990c1a4459ed5ee28e07ae8indicates -
154.211.86.110indicates -
https://nwphotoblog.comindicates -
103.214.172.33indicates -
2d2a251a88632f010fd9671789746908eeccaa5bc5c0a5d25e4649efe4f5b15dindicates -
ws.ztts88.cyouindicates -
206.238.115.58indicates