At a Glance
| Malware family | PackClient (RAT / C2 framework) |
| Threat actor | TA4922 (Chinese-speaking) – confirmed attribution by Proofpoint |
| Targets | Organizations in mainland China and India |
| Delivery vector | Tax-themed phishing emails with ZIP or IMG attachments |
| Key capabilities | Data theft, keylogging, screen capture, webcam, proxy tunneling, plugin loading |
| Source | Proofpoint Threat Insight |
TL;DR
Proofpoint discovered a new remote access trojan named PackClient that is sold on Telegram. At least one threat actor, Chinese-speaking TA4922, uses it in tax-themed phishing campaigns. The malware steals data, records keystrokes, and downloads extra plugins on command.
What Is the PackClient RAT?
PackClient is a modular command and control framework. Proofpoint researchers found it advertised on Chinese-language Telegram channels. The report describes it as a full featured RAT that “supports data theft, surveillance, and downloading of additional plugins and payloads.”
The framework splits into a first-stage loader, a launcher module, a core module, and optional plugins. Each plugin adds a feature such as screen capture or proxy tunneling. Operators pick what they need for each victim.
Delivery: Tax-Themed Phishing Lures

TA4922 relies on fear to push victims into action. In late May 2026, the actor impersonated the Shandong Provincial Tax Bureau. The emails claimed the target was selected for a 2026 tax inspection. They warned of penalties for anyone who ignored the notice.
Clicking the link downloaded a ZIP archive from the domain gov12366[.]com. Inside sat an executable that started the PackClient install. Later campaigns switched to Indian targets. Those emails posed as the Indian Income Tax Department and used Hindi-language enforcement lures.
Infection Chain
The infection runs in stages. A small downloader checks for elevated rights, then drops a DLL and fetches an encrypted payload. It decrypts that payload and sets registry autorun persistence.
The launcher module loads next. It contacts the primary C2 and pulls the core module, then loads it into memory. In the India campaigns, the actor added a twist. A mounted IMG disk image used DLL sideloading to run Donut Loader before installing PackClient.
A guard process also runs. It watches the main process and restarts it if defenders kill it. This process tree gives responders a useful hunting signal.
Command and Control and Data Exfiltration
The PackClient RAT talks to two C2 servers at once over raw TCP. Proofpoint noted the core module “accepts over 60 commands from the C2 server.” These cover file management, surveillance, and remote configuration.
The malware maps the victim system first. It lists running processes and flags security tools, browsers, and messaging apps. PackClient shows special interest in Telegram Desktop. A dedicated plugin can write to the local Telegram config and intercept traffic.
Stolen data leaves through the same custom protocol. The client sends desktop screenshots, keystrokes, and system details. Indicators of compromise include hardcoded C2 endpoints and a distinctive registry path under PackClientConsole.
Attribution
Proofpoint attributes these campaigns to TA4922 with confidence. The vendor links the tax lures, infrastructure, and payloads to the same actor. Wider adoption remains suspected, not confirmed. Because PackClient sells on Telegram, other Chinese-speaking groups may pick it up next.
Defense and Detection Guidance
Train staff to treat urgent tax notices with caution. Block execution of files from ZIP and mounted IMG archives where possible. Watch for the unusual PackClient process tree, especially a guard process spawned from a temp folder.
Monitor for autorun registry keys under RunOnce and for the PackClientConsole registry path. Flag unexpected outbound TCP to unfamiliar ports.
Why This Matters
Commodity malware lowers the bar for attackers. The PackClient RAT gives buyers a ready-made toolkit for spying and theft. As it spreads through Telegram, defenders should expect more actors and more campaigns using the same framework.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!