AI News Feed
Market watch
Companies

New PackClient RAT distributed via fake tax audit emails targets firms in China and India

Security researchers at Proofpoint have uncovered a malware campaign by the TA4922 group, which uses fake tax audit emails to deliver the PackClient remote access trojan to organizations in China and India.

The campaign has been active for nearly three months, according to a report published by Proofpoint. The attack group, tracked as TA4922, has been sending emails that spoof local tax authorities in China and India, telling recipients they are required to conduct a “self-inspection” and download paperwork attached to the message. The attachment is actually the PackClient installer.

Proofpoint said PackClient is being actively sold on Telegram channels. The trojan comes with a wide range of features, including file theft and management, remote shell execution, screen capture, remote desktop management, webcam access, keylogging, privilege escalation, and system administration.

The researchers noted that while PackClient is available on Telegram, TA4922 is the only hacking group observed using it so far. They described TA4922 as financially motivated rather than state-sponsored.

Proofpoint’s report did not specify how many organizations fell victim to the attack or which industries were most affected. In earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations, primarily in Japan, with additional targets in Taiwan, Korea, Singapore, and India. More recently, the group has also started targeting organizations in Europe and the UK.

Proofpoint warned that the advanced capabilities of PackClient could lead to wider adoption by other threat actors, potentially expanding campaigns to organizations in Western countries. “Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this malware in future campaigns,” the researchers said. They also shared a full list of indicators of compromise to help organizations check for potential infections.