TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India
TA4922 Deploys PackClient RAT via Tax-Themed Phishing (TL-2026-2202) is a high-severity malware campaign, first published 2026-08-29. It is attributed to TA4922 (China) with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1027, T1056, T1057), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2202
- Threat ID
- TL-2026-2202
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-29
- Last reviewed
- 2026-08-29
- Attribution
- TA4922
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- government administration, finance, tax and compliance, human resources and payroll
- Target regions
- china, india, East Asia
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in TA4922 Deploys PackClient RAT via Tax-Themed Phishing
Malware and tooling: PackClient, PackClientCore, PackClientLauncher, Donut Loader, ManageEngine RMM
Chinese-speaking threat actor TA4922 is distributing a Telegram-marketed C2 framework called PackClient (PackClientLauncher + PackClientCore) through tax-authority phishing lures impersonating the Shandong Provincial Tax Bureau (China) and the Indian Income Tax Department (Hindi-language, India). The India variant uses IMG disk images and DLL side-loading, and at least one intrusion progressed to deployment of ManageEngine RMM software for follow-on access.
How TA4922 Deploys PackClient RAT via Tax-Themed Phishing works
TA4922 is a Chinese-speaking threat group first observed by Proofpoint in spring 2025 targeting East Asia (primarily Japan) with regionalized HR/payroll/tax-themed phishing, later expanding into Europe and South Africa. The group is a customer of multiple commodity malware families sold through Chinese-language Telegram channels rather than a developer of bespoke tooling, and has previously been linked to Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT/Winos4.0.
In this campaign, TA4922 delivers PackClient, a modular C2 framework advertised on Telegram offering remote control, AV/Defender bypass, keylogging, and UAC-bypass features. PackClient is built in stages: a small initial downloader checks for elevated privileges, drops a DLL (e.g. xMain.dll) and launches it via `rundll32.exe "path\xMain.dll",XMain [URL] [C2_IP] [port]`; that DLL retrieves and XOR-decrypts an encrypted payload, writes it to `%TEMP%\svchost.exe`, and sets RunOnce registry persistence. The next stage, PackClientLauncher, contacts a C2 server over raw TCP to download PackClientCore and reflectively loads it into memory; it also spawns a `--guard` watchdog process that restarts the core module if killed. PackClientCore is the full RAT, supporting 60+ operator commands over two simultaneous, independently configured C2 channels (S1/S2), including shell execution, file management, process/security-product enumeration (with particular interest in Telegram Desktop and WeChat), screen and webcam capture, keylogging, clipboard capture, and a downloadable plugin system (screen control, file manager, remote terminal, proxy/SOCKS tunneling, and suspected browser-credential and Telegram-interception plugins). Configuration is persisted under `HKCU\SOFTWARE\PackClientConsole\`.
The first observed wave (late May 2026) targeted organizations with mainland China operations via emails impersonating the Shandong Provincial Tax Bureau, alleging missed stamp-duty payments and demanding self-inspection; the payload (`数据资料.zip` → `资料数据.exe`) was hosted on the actor-registered domain gov12366[.]com and an HFS (Rejetto HTTP File Server) instance at 154.36.188[.]98:8080, with C2 at 206.238.196[.]96:6666. A second wave beginning mid-July 2026 targeted organizations in India with Hindi-language emails impersonating the Indian Income Tax Department, alleging underreported income or undisclosed foreign assets. This chain delivers a ZIP containing an IMG disk image; mounting the IMG exposes a legitimate-looking executable alongside a malicious DLL (e.g. disguised as `nvdahelperremote.dll`), which is side-loaded to run a Donut Loader that in turn installs PackClient. In at least one India intrusion, ManageEngine remote monitoring and management software was installed a few hours after initial compromise, indicating a path toward broader remote access and potential follow-on operations (data theft, fraud, or access resale) beyond the initial RAT foothold; no ransomware deployment has been confirmed in current reporting. Proofpoint assesses TA4922 as Chinese-speaking/East-Asia-based on Chinese-language sample metadata, Chinese-provider infrastructure, and ecosystem overlap with the Silver Fox/Void Arachne malware-as-a-service community; this is a linguistic/infrastructure attribution, not a confirmed nation-state designation.
MITRE ATT&CK techniques used in TL-2026-2202
Defense Evasion
T1027 Obfuscated Files or Information; T1574 Hijack Execution Flow; T1620 Reflective Code Loading
Collection
T1056 Input Capture; T1113 Screen Capture; T1125 Video Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Command and Control
T1071 Application Layer Protocol; T1571 Non-Standard Port
defense-impairment
Execution
stealth
T1218 System Binary Proxy Execution
Persistence
T1547 Boot or Logon Autostart Execution
Credential Access
T1555 Credentials from Password Stores
Initial Access
Resource Development
Affected products and versions in TA4922 Deploys PackClient RAT via Tax-Themed Phishing
- Microsoft — Windows
Vulnerable versions: all supported Windows versions reachable via phishing delivery; no software vulnerability is exploited
Remediation for TA4922 Deploys PackClient RAT via Tax-Themed Phishing
Immediate actions
- Block the identified C2 IPs (206.238.196[.]96:6666, 64.81.30[.]99, 192.252.180[.]45:6666, 154.36.188[.]98:8080, 154.36.188[.]201, 192.229.87[.]219) and the phishing domain gov12366[.]com at the network perimeter
- Alert on rundll32.exe invoked with a URL, IP, and port as command-line arguments (xMain.dll pattern)
- Hunt for HKCU\SOFTWARE\PackClientConsole\ and the RunOnce\RuntimeBroker persistence entry pointing at %TEMP%\svchost.exe
- Quarantine and sandbox-analyze any ZIP or IMG email attachments referencing tax authorities (Shandong Provincial Tax Bureau, Indian Income Tax Department)
- Audit for unexpected ManageEngine RMM installations following any suspected PackClient infection
Workarounds
- Restrict execution of rundll32.exe from user-writable %TEMP% paths via application control policy
- Disable automatic mounting of ISO/IMG email attachments in mail clients where feasible
Longer-term hardening
- Deploy EDR with behavioral detection for reflective DLL loading and in-memory RAT cores, not just static AV signatures
- Restrict or scan mounting of ISO/IMG disk-image email attachments at the mail gateway
- Monitor for anomalous outbound TCP on port 6666 and other raw-TCP C2 beaconing patterns
- User awareness training on tax-authority phishing lures for organizations operating in China and India
Timeline of TA4922 Deploys PackClient RAT via Tax-Themed Phishing
- TA4922 first observed by Proofpoint in spring 2025, initially targeting East Asia (primarily Japan) with regionalized HR/payroll/tax-themed phishing.
- TA4922 campaigns expand into the UK, Germany, Italy, and South Africa (March-April 2026), continuing the group's rapid operational tempo and evolving malware arsenal.
- 206.238.196[.]96:6666 first observed as PackClient C2 infrastructure, predating the tax-themed campaigns by several months.
- PackClient campaign launched against organizations with mainland China operations; phishing impersonates the Shandong Provincial Tax Bureau, payload hosted on gov12366[.]com and an HFS server at 154.36.188[.]98:8080.
- India-focused campaign begins: Hindi-language Indian Income Tax Department lures deliver Tax_Notice_23665.zip/.img via IMG disk image and DLL side-loading (nvdahelperremote.dll); 64.81.30[.]99 observed as C2; ManageEngine RMM deployed within hours of compromise.
- Second India wave observed: new side-loaded DLL and IMG delivered; 192.252.180[.]45:6666 becomes active C2; 192.229.87[.]219 first seen as a ManageEngine RMM C2 server.
- Further India delivery wave: ITDTAX202601987.zip and Tax_Notice_00481.img distributed, with an additional side-loaded DLL.
- GBHackers publishes public reporting summarizing Proofpoint's PackClient/TA4922 research, surfacing the campaign to the TL-Intel Harness hunt pipeline.
Sources cited for TA4922 Deploys PackClient RAT via Tax-Themed Phishing
- Chinese Hackers Deploy PackClient RAT
- Carry-On Compromise: TA4922 Packs PackClient
- TA4922: The Suspected Chinese Crime Group is Going Global
- Proofpoint: TA4922 Deploys New RAT and Loader Arsenal
- TA4922 uses PackClient malware in tax phishing attacks
- Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
- PackClient RAT - Malware removal instructions
More in malware
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique
Detection coverage for TL-2026-2202
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2202 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2202
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.