China-linked TA4922 hackers target UK, Europe with new SilentRunLoader malware
A suspected China-aligned cybercrime group tracked as TA4922, previously known for targeting organisations in East Asia, is now running campaigns against organisations in the UK, Germany, Italy, and South Africa.
Proofpoint researchers said the group has increased its attacks in recent months, using familiar phishing tactics with a growing set of malware tools. The activity includes credential theft, fraud attempts, remote access malware and the use of legitimate remote management software to help maintain access inside victim networks.
For UK organisations, the most relevant activity involves emails designed to look like routine government or business communications. One campaign impersonated tax authorities and referenced VAT filings, payroll tax documents, and regulatory compliance. Another used benefits and compliance-themed messages that copied the language of government and universal benefits services.
Read more at HackRead