• Careful when filing your taxes, this new "PackClient" malware is

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 01, 2026 16:15:24
    Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures

    Date:
    Tue, 01 Sep 2026 15:00:00 +0000

    Description:
    The Chinese are using a tax lure to deploy a new RAT and take over victim devices.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922 Attack spoofed tax authority
    emails in China and India, delivering PackClient installer RAT offers
    advanced features; researchers warn broader adoption likely beyond Asia For almost three months, Chinese hackers have been distributing an advanced
    Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.

    According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things. Even though its actively sold
    on Telegram, so far just one hacking group was spotted using it - TA4922.
    This is not a state-sponsored group but rather a financially motivated one. Latest Videos From TechRadar Watch full video here: Picking up the malware Since late May 2026, this group has been mailing organization, first in
    China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct self-inspection, a process which included downloading and filling out paperwork shared in the attachment.

    The paperwork, however, was nothing more than the PackClient installer. You may like Watch out that income tax form could actually be dangerous malware Hackers caught hijacking this Chinese Windows VPN's installers to spread malware New malware disguised as popular Roblox cheat tool could give hackers full control of your PC

    In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.

    However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other
    notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those
    in the UK. Are you a pro? Subscribe to our newsletter Sign up to the
    TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.

    Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this malware in future campaigns, they said. The researchers also shared a full list of Indicators of Compromise ( IoC ), in case youre suspicious of an infection. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/careful-when-filing-your-taxes-this-new -packclient-malware-is-hitting-global-firms-via-tax-audit-lures


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)