TA4922 Turns Phishing Into Resaleable Remote Access

TA4922 is moving beyond ordinary email phishing. The group is using HR and business lures to start the contact, then pushing victims into Teams, WhatsApp, or LINE so the conversation stays alive outside normal mailbox controls and can end in remote access that can be sold or reused. Proofpoint says the campaign has expanded from East Asia into the U.K., Germany, Italy, and South Africa. It has also added undocumented loaders alongside ValleyRAT and Atlas RAT, with recent lures tied to HR, invoice, tax, benefits, and compliance themes. The defensive problem is no longer just filtering bad email. A blocked attachment or cleaned mailbox can still leave an active chat path and a live access foothold, which makes the compromise more durable than a one-off phishing hit.

Part of the PlainSec briefing for 2026-06-05

Sources