
TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia
A Chinese-speaking threat actor tracked as TA4922 is using tax-themed phishing campaigns to deploy PackClient, a modular remote access trojan (RAT) framework marketed through Telegram channels. Proofpoint researchers observed the group targeting organizations in mainland China and India during May and July 2026, using impersonated tax-authority notices to pressure recipients into opening malicious archives. The […]
The post TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia appeared first on Cyber Security News.