TA4922 Deploys PackClient RAT in Tax-Themed Phishing Campaigns Targeting China and India

· Original article ↗

Summary

Proofpoint details TA4922 campaigns using tax-themed phishing to install PackClient, a modular RAT sold on Telegram. The research describes its infection chain, capabilities, C2 communications, and detection opportunities.

Key points

  • Proofpoint observed TA4922 using PackClient in campaigns from May through July 2026 targeting organizations in China and India.
  • The campaigns impersonated tax authorities and used tax inspection or penalty lures to deliver malicious ZIP archives.
  • In India-focused campaigns, ZIP files contained IMG disk images whose executable and DLL used DLL sideloading and Donut Loader to install PackClient.
  • PackClient is a multistage RAT with a plugin system and more than 60 C2 commands, supporting surveillance, keylogging, data theft, remote access, and additional payload delivery.
  • The malware can maintain two C2 connections, persist through registry autorun entries, and use a guard process to restart its core process.
  • Proofpoint recommends hunting for its rundll32 launch pattern, temporary-directory svchost.exe processes, PackClient registry configuration, and anomalous TCP traffic; the malware’s use of port 6666 can be changed.

Article Details

Attack Vectors
  • Tax-themed phishing emails impersonated tax authorities and threatened penalties to pressure recipients into opening links or attachments.
  • The China-focused activity linked to an attacker-controlled site delivering a ZIP archive containing an executable that installed the RAT.
  • The India-focused activity delivered ZIP attachments containing IMG disk images. An executable and malicious DLL inside the mounted images used DLL sideloading to execute a loader and install the RAT.
  • The multistage infection downloaded additional executable modules and reflectively loaded the core module and optional plugins into memory.
  • Several hours after one initial infection, the actor deployed remote monitoring and management software as additional post-compromise tooling.
Defensive Notes
  • Hunt for rundll32 command lines invoking xMain.dll with the XMain export, a payload download URL, and a C2 address and port.
  • Inspect HKCU\SOFTWARE\PackClientConsole\ for malware configuration values.
  • Investigate the process chain rundll32.exe -> svchost.exe -> svchost.exe with a –guard parameter.
  • Investigate executables masquerading as Windows utilities in temporary directories, especially %TEMP%\svchost.exe.
  • Inspect HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce entries pointing to executables in temporary directories.
  • Investigate anomalous TCP port 6666 communications, while accounting for the operator's ability to change the port.
  • The article lists Emerging Threats detection rules 2018752, 2045860, 2018959, 2021076, 2069878, 2069879, 2069880, 2069881, 2069882, 2069883, 2069884, 2069885, 2069886, 2069887, 2066888, 2069889, and 2069890.

Indicators of compromise

TypeIndicatorContext
DOMAINgov12366[.]comAttacker-controlled domain delivering the ZIP archive 数据资料.zip used to install PackClient.
IPV4154[.]36[.]188[.]201Address identified in the IOC table as receiving post-infection traffic.
IPV4154[.]36[.]188[.]98Payload-hosting address serving the PackClientLauncher module and multiple .bin files over HTTP on port 8080.
IPV4192[.]229[.]87[.]219ManageEngine RMM server identified in the threat IOC table for the post-compromise activity.
IPV4192[.]252[.]180[.]45PackClient C2 address listed with port 6666 in the IOC table, first seen on 2026-07-20.
IPV4206[.]238[.]196[.]96Primary PackClient C2 address passed to the loader; communication used a custom TCP protocol on port 6666.
IPV464[.]81[.]30[.]99PackClient C2 infrastructure listed in the IOC table, first seen on 2026-07-15.
SHA256109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7Hash of 数据资料.zip, a ZIP archive delivering PackClient.
SHA25635712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9Hash of Tax_Notice_00481.img listed as a malicious disk-image artifact.
SHA25638ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04cHash of Tax_Notice_23665.img, the disk image used in the India-focused infection chain.
SHA2567108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85aHash of Tax_Notice_23665.zip, a malicious ZIP attachment.
SHA2567295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94Hash of nvdahelperremote.dll listed as an artifact of the malicious attachment activity.
SHA256832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242Hash of Tax_Notice_23709.img, a disk image in the malicious attachment infection chain.
SHA25683d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2Malware-related artifact hash explicitly listed in the IOC table; its filename is not disclosed.
SHA256aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69fHash of ITDTAX202601987.zip associated with activity first seen on 2026-07-22.
SHA256da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293Hash of ITDTAX202601987.zip, a malicious ZIP attachment associated with activity first seen on 2026-07-20.
SHA256fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53Hash of 资料数据[.]exe, an executable delivering PackClient.
URLhxxp[:]//154[.]36[.]188[.]98:8080/Sz9110[.]binNext-stage payload download URL passed to the dropped xMain.dll module.

MITRE ATT&CK

T1036.005 · Match Legitimate Resource Name or LocationPackClient used a temporary-directory executable named svchost.exe to masquerade as a legitimate Windows utility.T1041 · Exfiltration Over C2 ChannelPackClient transmitted screenshots to its C2 and supported synchronization of keylogger data through the C2 channel.T1056.001 · KeyloggingPackClient supported keylogger start, stop, offline recording, and synchronization of captured keystrokes to C2.T1057 · Process DiscoveryPackClient enumerated running processes and supported the Q|PROC|LIST command.T1059.003 · Windows Command ShellThe CMD|RUN command executed shell commands through cmd.exe and CreateProcessW.T1071.001 · Web ProtocolsThe initial downloader retrieved the PackClientLauncher payload over HTTP from the payload server on port 8080.T1082 · System Information DiscoveryC2 responses included the infected host's operating system version, machine GUID, and system architecture.T1083 · File and Directory DiscoveryPackClient's Q|FILE commands supported listing files and directories.T1090 · ProxyThe PXY command and proxy_tunnel plugin supported SOCKS/TCP proxy tunneling.T1095 · Non-Application Layer ProtocolPackClient used raw TCP sockets and a custom binary protocol for C2 communications, including observed connections on port 6666.T1105 · Ingress Tool TransferPackClient downloaded successive loader and core modules, additional plugins, and other payloads from its infrastructure.T1112 · Modify RegistryPackClient wrote configuration values under HKCU\SOFTWARE\PackClientConsole and supported registry read and write operations.T1113 · Screen CaptureResearchers observed PackClient sending thumbnail-sized desktop screenshots as JPEG data to its C2.T1115 · Clipboard DataThe core module included clipper capabilities and commands for clipper management.T1125 · Video CaptureThe WEBCAM command supported remote webcam video capture.T1140 · Deobfuscate/Decode Files or InformationThe initial loader XOR-decrypted the downloaded second-stage payload before writing the decrypted executable.T1204.002 · Malicious FileThe attachment infection chain relied on opening the delivered archive and mounted image containing the executable and malicious DLL.T1218.011 · Rundll32The initial loader invoked rundll32.exe to execute the XMain export of the dropped xMain.dll.T1518.001 · Security Software DiscoveryThe core module reported processes associated with AV and EDR software to the operator.T1547.001 · Registry Run Keys / Startup FolderThe loader established persistence through a HKCU RunOnce entry named RuntimeBroker pointing to an executable in the temporary directory.T1566.001 · Spearphishing AttachmentIndia-focused phishing emails delivered ZIP attachments containing IMG disk images and malicious execution components.T1566.002 · Spearphishing LinkTA4922 sent tax-themed emails linking to an attacker-controlled site that delivered a malicious ZIP archive.T1574.002 · DLL Side-LoadingAn executable in the IMG disk image sideloaded a malicious DLL to execute Donut Loader and install PackClient.T1620 · Reflective Code LoadingPackClientLauncher reflectively loaded the core PE into memory; plugin loading also copied DLLs into memory, resolved imports, and executed their main functions.

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles