TA4922 Deploys PackClient RAT in Tax-Themed Phishing Campaigns Targeting China and India

Summary
Proofpoint details TA4922 campaigns using tax-themed phishing to install PackClient, a modular RAT sold on Telegram. The research describes its infection chain, capabilities, C2 communications, and detection opportunities.
Key points
- Proofpoint observed TA4922 using PackClient in campaigns from May through July 2026 targeting organizations in China and India.
- The campaigns impersonated tax authorities and used tax inspection or penalty lures to deliver malicious ZIP archives.
- In India-focused campaigns, ZIP files contained IMG disk images whose executable and DLL used DLL sideloading and Donut Loader to install PackClient.
- PackClient is a multistage RAT with a plugin system and more than 60 C2 commands, supporting surveillance, keylogging, data theft, remote access, and additional payload delivery.
- The malware can maintain two C2 connections, persist through registry autorun entries, and use a guard process to restart its core process.
- Proofpoint recommends hunting for its rundll32 launch pattern, temporary-directory svchost.exe processes, PackClient registry configuration, and anomalous TCP traffic; the malware’s use of port 6666 can be changed.
Article Details
- Attack Vectors
- Tax-themed phishing emails impersonated tax authorities and threatened penalties to pressure recipients into opening links or attachments.
- The China-focused activity linked to an attacker-controlled site delivering a ZIP archive containing an executable that installed the RAT.
- The India-focused activity delivered ZIP attachments containing IMG disk images. An executable and malicious DLL inside the mounted images used DLL sideloading to execute a loader and install the RAT.
- The multistage infection downloaded additional executable modules and reflectively loaded the core module and optional plugins into memory.
- Several hours after one initial infection, the actor deployed remote monitoring and management software as additional post-compromise tooling.
- Defensive Notes
- Hunt for rundll32 command lines invoking xMain.dll with the XMain export, a payload download URL, and a C2 address and port.
- Inspect HKCU\SOFTWARE\PackClientConsole\ for malware configuration values.
- Investigate the process chain rundll32.exe -> svchost.exe -> svchost.exe with a –guard parameter.
- Investigate executables masquerading as Windows utilities in temporary directories, especially %TEMP%\svchost.exe.
- Inspect HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce entries pointing to executables in temporary directories.
- Investigate anomalous TCP port 6666 communications, while accounting for the operator's ability to change the port.
- The article lists Emerging Threats detection rules 2018752, 2045860, 2018959, 2021076, 2069878, 2069879, 2069880, 2069881, 2069882, 2069883, 2069884, 2069885, 2069886, 2069887, 2066888, 2069889, and 2069890.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | gov12366[.]com | Attacker-controlled domain delivering the ZIP archive 数据资料.zip used to install PackClient. |
| IPV4 | 154[.]36[.]188[.]201 | Address identified in the IOC table as receiving post-infection traffic. |
| IPV4 | 154[.]36[.]188[.]98 | Payload-hosting address serving the PackClientLauncher module and multiple .bin files over HTTP on port 8080. |
| IPV4 | 192[.]229[.]87[.]219 | ManageEngine RMM server identified in the threat IOC table for the post-compromise activity. |
| IPV4 | 192[.]252[.]180[.]45 | PackClient C2 address listed with port 6666 in the IOC table, first seen on 2026-07-20. |
| IPV4 | 206[.]238[.]196[.]96 | Primary PackClient C2 address passed to the loader; communication used a custom TCP protocol on port 6666. |
| IPV4 | 64[.]81[.]30[.]99 | PackClient C2 infrastructure listed in the IOC table, first seen on 2026-07-15. |
| SHA256 | 109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7 | Hash of 数据资料.zip, a ZIP archive delivering PackClient. |
| SHA256 | 35712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9 | Hash of Tax_Notice_00481.img listed as a malicious disk-image artifact. |
| SHA256 | 38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c | Hash of Tax_Notice_23665.img, the disk image used in the India-focused infection chain. |
| SHA256 | 7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a | Hash of Tax_Notice_23665.zip, a malicious ZIP attachment. |
| SHA256 | 7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94 | Hash of nvdahelperremote.dll listed as an artifact of the malicious attachment activity. |
| SHA256 | 832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242 | Hash of Tax_Notice_23709.img, a disk image in the malicious attachment infection chain. |
| SHA256 | 83d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2 | Malware-related artifact hash explicitly listed in the IOC table; its filename is not disclosed. |
| SHA256 | aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69f | Hash of ITDTAX202601987.zip associated with activity first seen on 2026-07-22. |
| SHA256 | da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293 | Hash of ITDTAX202601987.zip, a malicious ZIP attachment associated with activity first seen on 2026-07-20. |
| SHA256 | fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53 | Hash of 资料数据[.]exe, an executable delivering PackClient. |
| URL | hxxp[:]//154[.]36[.]188[.]98:8080/Sz9110[.]bin | Next-stage payload download URL passed to the dropped xMain.dll module. |
MITRE ATT&CK
T1036.005 · Match Legitimate Resource Name or LocationPackClient used a temporary-directory executable named svchost.exe to masquerade as a legitimate Windows utility.T1041 · Exfiltration Over C2 ChannelPackClient transmitted screenshots to its C2 and supported synchronization of keylogger data through the C2 channel.T1056.001 · KeyloggingPackClient supported keylogger start, stop, offline recording, and synchronization of captured keystrokes to C2.T1057 · Process DiscoveryPackClient enumerated running processes and supported the Q|PROC|LIST command.T1059.003 · Windows Command ShellThe CMD|RUN command executed shell commands through cmd.exe and CreateProcessW.T1071.001 · Web ProtocolsThe initial downloader retrieved the PackClientLauncher payload over HTTP from the payload server on port 8080.T1082 · System Information DiscoveryC2 responses included the infected host's operating system version, machine GUID, and system architecture.T1083 · File and Directory DiscoveryPackClient's Q|FILE commands supported listing files and directories.T1090 · ProxyThe PXY command and proxy_tunnel plugin supported SOCKS/TCP proxy tunneling.T1095 · Non-Application Layer ProtocolPackClient used raw TCP sockets and a custom binary protocol for C2 communications, including observed connections on port 6666.T1105 · Ingress Tool TransferPackClient downloaded successive loader and core modules, additional plugins, and other payloads from its infrastructure.T1112 · Modify RegistryPackClient wrote configuration values under HKCU\SOFTWARE\PackClientConsole and supported registry read and write operations.T1113 · Screen CaptureResearchers observed PackClient sending thumbnail-sized desktop screenshots as JPEG data to its C2.T1115 · Clipboard DataThe core module included clipper capabilities and commands for clipper management.T1125 · Video CaptureThe WEBCAM command supported remote webcam video capture.T1140 · Deobfuscate/Decode Files or InformationThe initial loader XOR-decrypted the downloaded second-stage payload before writing the decrypted executable.T1204.002 · Malicious FileThe attachment infection chain relied on opening the delivered archive and mounted image containing the executable and malicious DLL.T1218.011 · Rundll32The initial loader invoked rundll32.exe to execute the XMain export of the dropped xMain.dll.T1518.001 · Security Software DiscoveryThe core module reported processes associated with AV and EDR software to the operator.T1547.001 · Registry Run Keys / Startup FolderThe loader established persistence through a HKCU RunOnce entry named RuntimeBroker pointing to an executable in the temporary directory.T1566.001 · Spearphishing AttachmentIndia-focused phishing emails delivered ZIP attachments containing IMG disk images and malicious execution components.T1566.002 · Spearphishing LinkTA4922 sent tax-themed emails linking to an attacker-controlled site that delivered a malicious ZIP archive.T1574.002 · DLL Side-LoadingAn executable in the IMG disk image sideloaded a malicious DLL to execute Donut Loader and install PackClient.T1620 · Reflective Code LoadingPackClientLauncher reflectively loaded the core PE into memory; plugin loading also copied DLLs into memory, resolved imports, and executed their main functions.
Threat Actors
Malware
BillGatesValleyRat, ChinaZ, and BillGates are some notable examples.ChinaZValleyRat, ChinaZ, and BillGates are some notable examples.Donut LoaderWhen mounted, the image contained an executable and malicious DLL that leveraged DLL sideloading to execute Donut Loader and ultimately install PackClient.PackClientProofpoint identified a command and control (C2) framework called PackClient sold on Telegram.ValleyRATValleyRat, ChinaZ, and BillGates are some notable examples.
Vendors
Products
ManageEngine Remote Monitoring and ManagementThe threat actor subsequently deployed ManageEngine Remote Monitoring and Management (RMM) software several hours after the initial infection indicating additional post-compromise tooling.Microsoft WindowsFigure 11: The initial EXE payload requests another Windows executable over HTTP.Rejetto HTTP File ServerThe actors appear to be using Rejetto HTTP File Server (HFS) for hosting their payloads.TelegramProofpoint identified a command and control (C2) framework called PackClient sold on Telegram.Telegram DesktopAdditionally, PackClient seems to take a special interest in Telegram Desktop applications running on the infected system.
Tools
Countries
ChinaIn late May 2026, Proofpoint researchers identified a campaign attributed to TA4922 that targeted organizations with operations in mainland China that delivered a payload identified as part of the PackClient framework.IndiaIn mid-July 2026, the actor targeted organizations in India using Hindi-language tax enforcement lures that impersonated the Indian Income Tax Department.