HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

China‑Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa

TA4922, a China‑state‑aligned cybercrime group, has begun targeting European and African enterprises with spear‑phishing emails that deliver ValleyRAT and Atlas RAT. The campaign raises third‑party risk for organizations with cross‑border supply chains.

LiveThreat™ Intelligence · 📅 June 04, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

China‑Linked TA4922 Launches Phishing Campaign Targeting U.K., Germany, Italy, and South Africa Organizations

What Happened – A newly identified China‑state‑aligned cybercrime group, TA4922, has broadened its phishing operations to include enterprises in the United Kingdom, Germany, Italy, and South Africa. The group distributes malicious attachments that deploy RAT families such as ValleyRAT (Winos 4.0) and Atlas RAT (AtlasCross RAT).

Why It Matters for TPRM

  • Phishing is a primary entry point for credential theft and downstream supply‑chain compromise.
  • The rapid operational tempo and evolving malware toolkit increase the likelihood of successful compromise across multiple third‑party relationships.
  • Exposure of partner credentials can cascade to your own environment, even if you are not directly targeted.

Who Is Affected – Financial services, technology/SaaS providers, manufacturing, and other enterprises with cross‑border operations in the listed regions.

Recommended Actions

  • Review all third‑party access privileges for users in the affected regions.
  • Enforce multi‑factor authentication (MFA) on all vendor portals and remote access solutions.
  • Conduct phishing‑simulation training for both internal staff and critical suppliers.
  • Verify that endpoint detection and response (EDR) solutions can detect ValleyRAT and Atlas RAT signatures.

Technical Notes – The campaign relies on spear‑phishing emails with malicious Office documents that execute PowerShell payloads to drop the RATs. No public CVE is associated; the threat leverages known malware families rather than zero‑day exploits. Data types at risk include login credentials, internal communications, and potentially exfiltrated intellectual property. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.