Breaking
September 1, 2026

Careful when filing your taxes, this new “PackClient” malware is hitting global firms via tax audit lures | usagoldmines.com

  • Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922
  • Attack spoofed tax authority emails in China and India, delivering PackClient installer
  • RAT offers advanced features; researchers warn broader adoption likely beyond Asia

For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.

According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.

Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it – TA4922. This is not a state-sponsored group but rather a financially motivated one.

Picking up the malware

Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.

The “paperwork”, however, was nothing more than the PackClient installer.

In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.

However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK.

Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.

“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this malware in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (IoC), in case you’re suspicious of an infection.

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.