Chinese Threat Actor TA4922 Leverages PackClient RAT in Phishing Campaigns
Financially motivated Chinese-speaking threat actor TA4922 is employing the modular PackClient remote access trojan, acquired from commodity marketplaces, in sophisticated phishing campaigns targeting organizations in China and India.

A financially motivated Chinese-speaking threat actor, identified as TA4922, has adopted a new remote access trojan (RAT) framework named PackClient, likely purchased from online malware marketplaces. Security firm Proofpoint reports that this modular RAT enables the group to conduct extensive surveillance, data theft, and post-compromise operations. TA4922 has been observed using this tool in at least three distinct campaigns since May 2026, primarily targeting organizations within China and India.
Proofpoint notes a concerning trend of Chinese-speaking threat actors increasingly utilizing new malware families emerging from these commodity markets. TA4922 alone has been linked to at least half a dozen such families, indicating a growing reliance on readily available, sophisticated tools. PackClient, advertised on Telegram in Chinese, is presented as a comprehensive solution offering advanced features such as remote control, antivirus evasion, system management, keylogging, and payload deployment.
The PackClient malware operates in stages, beginning with a small initial executable that checks for elevated privileges before dropping a dynamic-link library (DLL). This is followed by a second-stage launcher module that establishes communication with the command-and-control (C2) server and downloads the core payload. The core module, PackClientCore, is designed with modularity in mind, supporting numerous commands and multiple, independently configured C2 connections.
One particularly noteworthy feature of PackClient is its apparent interest in Telegram Desktop applications. Analysis suggests the malware can download a specialized plugin to interact with Telegram's local configuration files. This capability could allow attackers to intercept and manipulate Telegram traffic, effectively enabling man-in-the-middle attacks on the host system's communications.
TA4922 has employed diverse phishing tactics to distribute PackClient. In late May, the group sent tax-themed lures in Chinese, impersonating the Shandong Provincial Tax Bureau. These emails directed recipients to a malicious link that downloaded a ZIP archive containing the initial PackClient executable. More recently, in mid-July, the actor used Hindi-language lures, posing as the Indian Income Tax Department, to trick victims into downloading an IMG disk image containing the malware.
The distribution method in the Indian campaign involved a more complex chain, leveraging DLL sideloading to execute a Donut Loader before ultimately installing PackClient. In addition to deploying the RAT, TA4922 has also been observed installing ManageEngine remote monitoring and management software within hours of initial compromise, suggesting a strategy of establishing persistent access and deploying additional post-compromise tools.
While current victimology is concentrated in Asia, Proofpoint warns that TA4922 has a history of expanding its operations globally. The group has previously targeted organizations in Japan, Singapore, Germany, and the United Kingdom using AI-assisted multilingual lures. This suggests that organizations outside of Asia should also remain vigilant.
To detect PackClient infections, organizations can look for specific Rundll32 command-line patterns, PackClient configuration data stored in the Windows registry, and anomalous network communications, particularly over TCP port 6666. The presence of malware masquerading as legitimate Windows utilities in temporary directories is also a potential indicator.