Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures

https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-2560-80.jpg
  • Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922
  • Attack spoofed tax authority emails in China and India, delivering PackClient installer
  • RAT offers advanced features; researchers warn broader adoption likely beyond Asia

For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.

According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.

Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.

Picking up the malware

Since late May 2026, this group has been mailing organization,...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more