Cyber Security News

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting organizations in mainland China and India.

The activity, observed by Proofpoint in May and July 2026, demonstrates the group’s expanding initial-access capabilities and the increasing availability of sophisticated malware on Chinese-language Telegram marketplaces.

PackClient is a modular remote access trojan framework that can support espionage, financial fraud, reconnaissance, credential theft, data exfiltration, and follow-on ransomware operations.

The framework is sold through Telegram channels and includes an initial downloader, a second-stage loader called PackClientLauncher, the PackClientCore RAT module, and downloadable plugins. The first campaign emerged in late May and impersonated the Shandong Provincial Tax Bureau.

Chinese Hackers Deploy PackClient RAT

TA4922 sent emails claiming that recipient organizations had been selected for a 2026 tax inspection and had allegedly failed to pay stamp duties on purchase, sale, and lease contracts. The attackers used regulatory pressure and possible financial penalties to persuade targets to open malicious files.

Victims were directed to download a ZIP archive named 数据资料.zip from gov12366[.]com, an actor-controlled domain designed to resemble a government tax service.

The archive contained 资料数据.exe, which launched the PackClient infection chain. The first-stage downloader checks whether it has elevated permissions, drops a DLL such as xMain.dll, and executes it using rundll32.exe.

The downloader then retrieves an encrypted payload, decrypts it, and writes it to disk under a masqueraded filename, commonly %TEMP%\svchost.exe.

Tax Phishing (Source: proofpoint)

To survive system restarts, the malware creates a RunOnce registry persistence entry and launches the payload. This use of a temporary-directory executable and a trusted Windows utility can make the initial execution sequence harder to identify without endpoint telemetry.

TA4922 subsequently adapted the operation for Indian targets. In mid-July, the group distributed Hindi-language emails impersonating the Indian Income Tax Department.

The messages accused recipients of underreporting income or failing to disclose foreign assets, threatened penalties, and directed targets to review the attached tax material.

The India-focused messages used ZIP archives such as Tax_Notice_23665.zip and ITDTAX202601987.zip. Each archive contained an IMG disk-image file.

When mounted, the image exposed an executable and a malicious DLL. The attackers used DLL sideloading to launch Donut Loader, which ultimately installed PackClient on the device.

Proofpoint observed PackClient-associated post-compromise traffic to 64[.]81[.]30[.]99 during one campaign. In another, compromised hosts communicated with 192[.]252[.]180[.]45 using TCP port 6666.

Several hours after one initial infection, the attackers installed ManageEngine Remote Monitoring and Management software, indicating an attempt to expand remote access and potentially facilitate interactive operations across the victim environment.

The PackClientLauncher component downloads and reflectively loads PackClientCore into memory. The RAT supports two concurrent command-and-control channels and more than 60 commands.

It can execute shell commands, manage files, enumerate processes, capture screenshots, access webcams, record keystrokes, collect browser data, modify the registry, create proxy tunnels, manipulate clipboard data, and download further plugins.

Researchers also found that PackClient checks for Telegram Desktop. A potential plugin may modify local Telegram configuration data, potentially allowing attackers to intercept or monitor communications.

PackClient stores its configuration in HKCU\SOFTWARE\PackClientConsole\, including C2 servers, ports, campaign identifiers, system UUIDs, and installation timestamps.

Defenders should hunt for rundll32.exe loading DLLs from temporary directories, RunOnce entries starting %TEMP%\svchost.exe, and processes using the svchost.exe --guard argument.

The guard process monitors the RAT and restarts it after termination. Organizations should also investigate unexpected outbound TCP traffic on port 6666, tax-themed ZIP or IMG attachments, and unapproved deployment of remote-management software.

IOCs

IndicatorTypeDescription
154.36.188[.]98:8080IP address and portHTTP server used to download the PackClient launcher module.
206.238.196[.]96:6666IP address and portPackClient command-and-control server communicating over raw TCP.
gov12366[.]comDomainAttacker-controlled domain hosting the China-focused tax phishing payload.
109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7SHA-256Malicious ZIP archive named 数据资料.zip used to deliver PackClient.
fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53SHA-256Executable 资料数据[.]exe contained in the China-themed phishing archive.
64.81.30[.]99IP addressPackClient C2 infrastructure observed during the India-focused campaign.
192.252.180[.]45:6666IP address and portPackClient C2 endpoint used in the later Indian tax-lure campaign.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Eswar

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model…

18 hours ago

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after…

19 hours ago

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page…

19 hours ago

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…

20 hours ago

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…

20 hours ago

Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days

A cyber incident reportedly forced a small UK power generation facility offline for about four…

20 hours ago