Minacce · 117 giorni fa
TA4922 si sta muovendo oltre il normale phishing via email. Il gruppo sta usando esche HR e business per avviare il contatto, poi spinge le vittime su Teams, WhatsApp o LINE così che la conversazione resti attiva al di fuori dei normali controlli della mailbox e possa sfociare in un accesso remoto che può essere venduto o riutilizzato.
3 fonti che coprono questa storia
China's TA4922 Expands Cybercrime Attacks Globally
One of the world's most diverse, least-focused cybercrime groups has been spreading its activity beyond East Asia.
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
TA4922 expanded targeting to organizations in the U.K., Germany, Italy, and South Africa while continuing campaigns against East Asia.
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
TA4922 expanded targeting to organizations in the U.K., Germany, Italy, and South Africa while continuing campaigns against East Asia.
Part of the PlainSec briefing for 2026-06-05