Skip to content
Live newsroom 144 readers online
Wednesday, September 2, 2026 Live Sync: Just now
BreakingAriana Madix, now
Share Suggestions AVOID AMZN Stage 4 (Conv: 1/5 | Size: 10%)

Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures

The Chinese are using a tax lure to deploy a new RAT When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India. According […]

By deepak · September 1, 2026 · 3 min read

The Chinese are using a tax lure to deploy a new RAT

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.

According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.

Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it – TA4922. This is not a state-sponsored group but rather a financially motivated one.

Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.

The “paperwork”, however, was nothing more than the PackClient installer.

In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.

However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.

“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this malware in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (IoC), in case you’re suspicious of an infection.

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Source: Read the original article on www.techradar.com

Important Legal & Financial Disclaimer

FutureKnowledge is an automated financial intelligence aggregator. The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website's content as such. We are not registered with the SEC, SEBI, or any regulatory agency. Automated AI-generated content may contain errors. Always conduct your own due diligence and consult your financial advisor before making any investment decisions.

© 2026 FutureKnowledge Intelligence. All rights reserved.