Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

TA4922 Deploys PackClient RAT via Tax‑Inspection Phishing Campaigns Targeting China and India

Proofpoint identified a Telegram‑sold RAT framework called PackClient being used by the Chinese‑language group TA4922 in tax‑inspection phishing campaigns against organizations in China and India. The attacks deliver malicious archives that install a modular C2 client, highlighting the need for robust security‑awareness controls in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 proofpoint.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
proofpoint.com

TA4922 Deploys PackClient RAT via Tax‑Inspection Phishing Campaigns Targeting China and India

What Happened — Proofpoint researchers uncovered a modular Remote Access Trojan (RAT) framework called PackClient being sold on Telegram. The Chinese‑language cybercrime group TA4922 has used PackClient in at least three phishing campaigns (May‑July 2026), delivering the payload through tax‑inspection lures that impersonate the Shandong Provincial Tax Bureau (China) and the Indian Income Tax Department (India).

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates a classic phishing‑based initial‑access scenario that SOC 2 Security and Risk Management criteria require you to detect, log, and remediate.
  • Continuous evidence of a Security Awareness Training program (e.g., phishing simulations, training completion records) serves as audit‑ready proof that your organization mitigates this high‑frequency attack vector.
  • Verisq’s Security Awareness capability provides the tooling to track training effectiveness and generate the documentation auditors expect for the SOC 2 CC6.1 control.

Who Is Affected

  • Enterprises with operations in mainland China
  • Enterprises with operations in India
  • Any organization that relies on email for tax‑related communications

Recommended Actions

  • Map the phishing scenario to SOC 2 CC6.1 (Security Awareness) and ensure training records are collected in a tamper‑evident repository.
  • Deploy regular, role‑based phishing simulations that mimic tax‑inspection lures and capture click‑through metrics.
  • Enforce DMARC, DKIM, and SPF to reduce spoofed tax‑bureau emails reaching users.
  • Update incident‑response playbooks to include rapid isolation of compromised endpoints running unknown executables.

Source: Proofpoint Threat Insight – Carry‑On Compromise: TA4922 Packs PackClient

Technical Notes

  • Attack vector: Phishing email with tax‑inspection notice → malicious ZIP/IMG archive → executable that installs PackClient.
  • Payload: PackClient RAT (modular C2, data theft, surveillance, plugin download).
  • Infrastructure: Actor‑controlled domain gov12366.com; delivery via ZIP (数据资料.zip) and IMG (Tax_Notice_23665.img).
  • Languages: Chinese‑language lure (China) and Hindi‑language lure (India).
📰 Original Source
https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →