TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India — Threadlinqs Intelligence
As of 2026-08-29, TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India is a high-severity malware threat attributed to TA4922 (CN), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2202 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: TA4922 · CN · FINANCIAL
Chinese-speaking threat actor TA4922 is distributing a Telegram-marketed C2 framework called PackClient (PackClientLauncher + PackClientCore) through tax-authority phishing lures impersonating the
TA4922 is a Chinese-speaking threat group first observed by Proofpoint in spring 2025 targeting East Asia (primarily Japan) with regionalized HR/payroll/tax-themed phishing, later expanding into Europe and South Africa. The group is a customer of multiple commodity malware families sold through Chinese-language Telegram channels rather than a developer of bespoke tooling, and has previously been linked to Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT/Winos4.0.
In this campaign, TA4922 delivers PackClient, a modular C2 framework advertised on Telegram offering remote control, AV/Defender bypass, keylogging, and UAC-bypass features. PackClient is built in stages: a small initial downloader checks for elevated privileges, drops a DLL (e.g. xMain.dll) and launches it via `rundll32.exe "path\xMain.dll",XMain [URL] [C2_IP] [port]`; that DLL retrieves and XOR-decrypts an encrypted payload, writes it to `%TEMP%\svchost.exe`, and sets RunOnce registry persistence. The next stage, PackClientLauncher, contacts a C2 server over raw TCP to download PackClientCore and reflectively loads it into memory; it also spawns a `--guard` watchdog process that restarts the core module if killed. PackClientCore is the full RAT, supporting 60+ operator commands over two simultaneous, independently configured C2 channels (S1/S2), including shell execution, file management, process/security-product enumeration (with particular interest in Telegram Desktop and WeChat), screen and webcam capture, keylogging, clipboard capture, and a downloadable plugin system (screen control, file manager, remote terminal, proxy/SOCKS tunneling, and suspected browser-credential and Telegram-interception plugins). Configuration is persisted under `HKCU\SOFTWARE\PackClientConsole\`.
The first observed wave (late May 2026) targeted organizations with mainland China operations via emails impersonating the Shandong Provincial Tax Bureau, alleging missed stamp-duty payments and demanding self-inspection; the payload (`数据资料.zip` → `资料数据.exe`) was hosted on the actor-registered domain gov12366[.]com and an HFS (Rejetto HTTP File Server) instance at 154.36.188[.]98:8080, with C2 at 206.238.196[.]96:6666. A second wave beginning mid-July 2026 targeted organizations in India with Hindi-language emails impersonating the Indian Income Tax Department, alleging underreported income or undisclosed foreign assets. This chain delivers a ZIP containing an IMG disk image; mounting the IMG exposes a legitimate-looking executable alongside a malicious DLL (e.g. disguised as `nvdahelperremote.dll`), which is side-loaded to run a Donut Loader that in turn installs PackClient. In at least one India intrusion, ManageEngine remote monitoring and management software was installed a few hours after initial compromise, indicating a path toward broader remote access and potential follow-on operations (data theft, fraud, or access resale) beyond the initial RAT foothold; no ransomware deployment has been confirmed in current reporting. Proofpoint assesses TA4922 as Chinese-speaking/East-Asia-based on Chinese-language sample metadata, Chinese-provider infrastructure, and ecosystem overlap with the Silver Fox/Void Arachne malware-as-a-service community; this is a linguistic/infrastructure attribution, not a confirmed nation-state designation.
Target sectors: government administration, finance, tax and compliance, human resources and payroll
Target regions: china, india, East Asia
Timeline
- TA4922 first observed by Proofpoint in spring 2025, initially targeting East Asia (primarily Japan) with regionalized HR/payroll/tax-themed phishing.
- TA4922 campaigns expand into the UK, Germany, Italy, and South Africa (March-April 2026), continuing the group's rapid operational tempo and evolving malware arsenal.
- 206.238.196[.]96:6666 first observed as PackClient C2 infrastructure, predating the tax-themed campaigns by several months.
- PackClient campaign launched against organizations with mainland China operations; phishing impersonates the Shandong Provincial Tax Bureau, payload hosted on gov12366[.]com and an HFS server at 154.36.188[.]98:8080.
- India-focused campaign begins: Hindi-language Indian Income Tax Department lures deliver Tax_Notice_23665.zip/.img via IMG disk image and DLL side-loading (nvdahelperremote.dll); 64.81.30[.]99 observed as C2; ManageEngine RMM deployed within hours of compromise.
- Second India wave observed: new side-loaded DLL and IMG delivered; 192.252.180[.]45:6666 becomes active C2; 192.229.87[.]219 first seen as a ManageEngine RMM C2 server.
- Further India delivery wave: ITDTAX202601987.zip and Tax_Notice_00481.img distributed, with an additional side-loaded DLL.
- GBHackers publishes public reporting summarizing Proofpoint's PackClient/TA4922 research, surfacing the campaign to the TL-Intel Harness hunt pipeline.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1588, T1566, T1204, T1218, T1547, T1574, T1027, T1620, T1112