A new remote access trojan called PackClient is spreading through fake tax audit emails, hitting organizations in China and India.
Since late May 2026, a financially motivated group tracked as TA4922 has been emailing organizations in China and India while posing as local tax authorities, telling recipients to complete a "self-inspection" by filling out attached paperwork that is actually a PackClient installer. Once running, the RAT can steal and manage files, open a remote shell, capture screens and desktops, hijack webcams, log keystrokes, and escalate privileges, according to security firm Proofpoint. Proofpoint has tracked TA4922 for longer than this campaign, and says the group has previously hit small and mid sized businesses in Japan, Taiwan, Korea, Singapore, and India, more recently expanding to organizations in Europe and the UK. The firm has not disclosed how many organizations fell for the current campaign or which industries were hit hardest.
The bigger story is distribution: PackClient is sold openly on Telegram, so it isn't locked to TA4922 - any buyer with access to that channel can deploy it. A RAT with this feature set usually stays exclusive to whoever commissions it, and Proofpoint expects wider adoption, especially against organizations further west, given how cheaply it turns bespoke spyware into a commodity.
Tax deadlines make reliable phishing bait every year, but a capable spy tool for sale on a chat app - deployed by a group with a track record of following its targets westward - is the part worth watching.