PackClient RAT Targets Global Firms via Tax Phishing Campaigns

PackClient RAT Targets Global Firms via Tax Phishing Campaigns

First seen 1 Sep 2026, 22:29 UTC TechradarSocprime 68.0

Article Content

Browse articles
ThreatCluster

TA4922, a financially motivated threat actor, has been distributing the PackClient RAT since late May 2026, primarily targeting organizations in China and India. The malware is delivered through spoofed emails claiming to be from local tax authorities, urging recipients to download malicious attachments. PackClient offers advanced features such as remote access, file theft, and keylogging. Researchers from Proofpoint have confirmed the malware's availability on Telegram, indicating a potential for broader adoption by other threat actors. The attack has raised concerns about its impact on small and medium-sized enterprises, particularly in Asia, with indications that it may expand to Western organizations. Organizations are advised to monitor for suspicious activity and implement strict controls on executable downloads. The current status of the campaign is active, with ongoing distribution and exploitation efforts.

Key Points: • PackClient RAT is distributed via tax-themed phishing emails. • Targeted organizations include those in China and India, with potential expansion to the West. • The malware offers advanced capabilities like remote access and data theft.

Timeline

2026-05-01
PackClient RAT distribution begins
TA4922 starts sending spoofed emails claiming to be from tax authorities in China and India.
Techradar
2026-09-01
PackClient malware identified
Proofpoint researchers confirm the use of PackClient in phishing campaigns targeting organizations in Asia.
Socprime
2026-09-01
PackClient's capabilities detailed
PackClient is reported to have advanced features including remote shell execution and keylogging.
Techradar