CyberSecurity SEE

Chinese Hackers Use Tax-Themed Phishing Attacks to Deploy PackClient RAT and Steal Data

Chinese Hackers Use Tax-Themed Phishing Attacks to Deploy PackClient RAT and Steal Data

A recently identified threat actor, designated as TA4922, is reportedly conducting tax-themed phishing campaigns that deploy the sophisticated PackClient remote access trojan (RAT). This group’s activities are primarily focused on targeting organizations in mainland China and India, with significant implications for cybersecurity.

The malicious operations of TA4922 were notably observed during May and July of 2026, as documented by cybersecurity researchers at Proofpoint. The group’s capabilities appear to be evolving, showcasing an increased proficiency in initial-access methodologies alongside the availability of advanced malware within Chinese-language Telegram marketplaces.

The PackClient Framework

PackClient is classified as a modular RAT framework that excels in various clandestine operations, including espionage, financial fraud, reconnaissance, credential theft, data exfiltration, and even potential follow-on ransomware operations. The framework’s distribution takes place through specific Telegram channels, where it comprises several critical components: an initial downloader, a secondary loader known as PackClientLauncher, the main PackClientCore RAT module, and a collection of downloadable plugins.

The debut of this malware campaign occurred in late May when the attackers masqueraded as representatives from the Shandong Provincial Tax Bureau, a tactic intended to lend credibility to their phishing attacks. Victims received communications that asserted they had been selected for a 2026 tax inspection and accused them of failing to pay statutory stamp duties on various contracts related to purchases, sales, and leases. By applying pressure through regulatory threats and potential financial penalties, TA4922 effectively manipulated targets into downloading malicious files.

Phishing Techniques and Mechanisms

The phishing emails instructed recipients to download a ZIP archive labeled "数据资料.zip" from an actor-controlled domain, gov12366.com, which was designed to mimic an official government tax service. Within the downloaded archive, a file named "资料数据.exe" initiates the PackClient infection chain. The downloader first checks for elevated system permissions, subsequently drops a DLL file like "xMain.dll," and executes it using the legitimate Windows utility rundll32.exe.

After this initial execution, the downloader fetches an encrypted payload, decrypts it, and saves it to the system, usually as "%TEMP%\svchost.exe." Such tactics allow the malware to evade detection mechanisms, particularly following system restarts. The malware also creates a registry persistence entry under "RunOnce," ensuring that it remains functional even after system reboots.

In a strategic pivot, TA4922 adjusted its operational focus toward Indian organizations by mid-July, utilizing Hindi-language emails that impersonated the Indian Income Tax Department. These communications accused recipients of underreporting income or failing to declare foreign assets, further leveraging threats of penalties to coerce individuals into opening attached tax-related materials.

Adapting Strategies for Indian Targets

The targeted phishing messages utilized ZIP files such as "Tax_Notice_23665.zip" and "ITDTAX202601987.zip," which contained IMG disk images. When mounted, these images revealed an executable file alongside a malicious DLL. Through a method known as DLL sideloading, the attackers deployed Donut Loader, which ultimately resulted in the installation of PackClient on the victim’s device.

Further analyses revealed that PackClient-associated communications were routed to specific IP addresses, such as 64.81.30.99, during one campaign, while another involved compromised hosts connecting to 192.252.180.45 over TCP port 6666. Several hours post-infection, the attackers deployed ManageEngine Remote Monitoring and Management software, signaling an intent to enhance remote access and facilitate interactive operations within the compromised environments.

PackClient’s architecture is particularly concerning. The PackClientLauncher component is capable of downloading and reflectively loading PackClientCore directly into memory. It supports two simultaneous command-and-control channels and encompasses more than 60 commands, allowing it to perform a variety of nefarious activities. These include executing shell commands, managing files, enumerating processes, capturing screenshots, accessing webcams, recording keystrokes, collecting browser data, modifying the registry, and creating proxy tunnels.

Recommendations for Safeguarding Against PackClient

Research indicates that PackClient actively checks for the presence of Telegram Desktop, potentially allowing attackers to intercept or eavesdrop on communications through its plugins. The malware’s configuration is stored in "HKCU\SOFTWARE\PackClientConsole," housing critical operational data such as command-and-control server addresses and installation timestamps.

To defend against such evolving threats, organizations are urged to monitor for instances of rundll32.exe executing DLL files from temporary directories, alongside examining unusual outbound TCP traffic on port 6666 and tax-themed attachments. Security teams should also be vigilant against any unapproved deployment of remote-management software in their environments.

Indicators of Compromise (IOCs) associated with this malware campaign include specific malicious IP addresses, domain names, and SHA-256 hashes related to the deployed malware. Cybersecurity teams are encouraged to investigate these indicators as part of their proactive cyber defense strategies.

The visibility into the strategies employed by TA4922 highlights the importance of continuous vigilance and appropriate response mechanisms in navigating the complex landscape of cyber threats today.

Source link

Exit mobile version