Proofpoint identified Chinese-speaking threat actor TA4922 delivering the modular PackClient remote-access trojan (RAT) and command-and-control framework through tax-themed phishing. In late May 2026, the actor impersonated the Shandong Provincial Tax Bureau to target organizations in mainland China; in July, it used Hindi-language messages posing as the Indian Income Tax Department against Indian organizations. The Indian lures delivered ZIP archives containing IMG files and used DLL sideloading to install the malware.
PackClient, advertised through Chinese-language Telegram channels, supports dual C2 connections, persistence, process monitoring, screen and webcam capture, keylogging, clipboard theft, proxy tunneling, file and shell operations, and downloadable plugins. Its emergence follows prior reporting on updated ValleyRAT variants, underscoring continued development and distribution of feature-rich RATs within the Chinese-speaking threat ecosystem; PackClient's marketing may also enable adoption by additional actors.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
After a PackClient infection began on 20 July, operators suppressed UAC prompts and installed an attacker-controlled ManageEngine Endpoint Central UEMS agent. The agent enabled Active Directory enumeration, vulnerability scanning, remote control, and deployment of DeviceControl, BitLocker-management, and anti-ransomware/EDR modules.
From 20 to 22 July 2026, TA4922 conducted another India-focused tax-themed campaign using ITDTAX202601987.zip and IMG attachments including Tax_Notice_23709.img. PackClient communicated with 192[.]252[.]180[.]45 over TCP port 6666, and the actor deployed ManageEngine Remote Monitoring and Management software several hours after infection.
In mid-July 2026, TA4922 targeted organizations in India with Hindi-language lures impersonating the Indian Income Tax Department. ZIP archives containing IMG files used DLL sideloading and Donut Loader to install PackClient, with post-compromise communications to 64[.]81[.]30[.]99.
In late May 2026, the Chinese-speaking threat actor TA4922 sent tax-inspection phishing emails impersonating the Shandong Provincial Tax Bureau to organizations operating in mainland China. The campaign directed victims to download 数据资料.zip from gov12366[.]com, which contained an executable that installed PackClient.
TA4922 recently expanded its targeting beyond East Asia to organizations in Europe and the United Kingdom, according to the reference. No specific campaign dates, victims, or technical details for this expansion were provided.
Researchers released detection indicators for PackClient activity associated with TA4922, including gov12366.com, six IP addresses, and ten SHA-256 hashes. The report also described PackClient as a Telegram-sold modular framework capable of data theft, surveillance, and downloading further payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 38 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecommunity.gurucul.com
Open sourceblog.deception.pro
Open sourceproofpoint.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.