TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia
Brief
A Chinese-speaking threat actor tracked as TA4922 is using tax-themed phishing campaigns to deploy PackClient, a modular remote access trojan (RAT) framework marketed through Telegram channels.
Proofpoint researchers observed the group targeting organizations in mainland China and India during May and July 2026, using impersonated tax-authority notices to pressure recipients into opening malicious archives.
The activity signals an expansion of TA4922’s initial-access toolkit and highlights the growing availability of sophisticated malware in Chinese-speaking cybercrime marketplaces.
TA4922 Hackers Use Tax Phishing
PackClient provides operators with data-theft, surveillance, remote control, payload delivery, and persistence capabilities, making it suitable for espionage, financial crime, reconnaissance, or follow-on ransomware operations.
