Cybercrime: New Findings on Chinese-Speaking Threat Actor TA4922
In a comprehensive analysis, security firm Proofpoint has highlighted the alarming advancements made by a financially motivated cybercrime group known as TA4922, which operates primarily in Chinese-speaking regions. This group has reportedly adopted a sophisticated remote access Trojan (RAT) framework that appears to have been obtained through online malware marketplaces.
The Nature of TA4922’s Operations
TA4922 has become known for its methodical approach to cyber intrusions, predominantly utilizing phishing emails to disseminate a powerful command-and-control framework, identified as PackClient. This framework is not only capable of enabling extensive data theft but also allows for sophisticated surveillance operations. Additionally, it facilitates the downloading of various plugins and additional malicious payloads, thereby expanding the capabilities of the malware.
The group has previously utilized AI-assisted loader families and malware payloads earlier in 2026, particularly in March and April. However, a noticeable shift occurred in May when they transitioned to using PackClient. This shift was observed across at least three targeted campaigns, primarily aimed at organizations in China and India.
Proofpoint’s investigation reveals that the overall landscape of Chinese-speaking malware ecosystems is evolving rapidly. The firm notes an uptick in malware emergence from these areas compared to previous years. TA4922 is believed to be a customer of multiple malware families, indicating a broader and more fragmented ecosystem than before. This surge might be attributed not only to intensified hunting and detection efforts on the part of cybersecurity professionals but also to the proliferation of new malware variants available for purchase on various online platforms.
Features of PackClient
PackClient offers a plethora of functional capabilities that make it a versatile weapon in the hands of cybercriminals. Advertised in Mandarin on messaging app Telegram, it promises features such as remote control, evasion techniques against leading antivirus software, keylogging, and even system management functions. According to Proofpoint, PackClient includes a first-stage loader executable, a secondary stage loader known as the "PackClientLauncher," a core module dubbed "PackClientCore," along with several optional plugins that can be installed as per the attacker’s discretion.
The initial executable’s primary function is to check for elevated permissions on the system, subsequently deploying a dynamic-link library (DLL) referred to as "xMain.dll" for execution. Once activated, the launcher module establishes a connection with the primary command-and-control (C2) server and facilitates the download of critical payloads.
PackClientCore stands out due to its capacity to manage multiple C2 server connections, accept over 60 different commands, log keystrokes, and manipulate clipboard data. Importantly, it appears to exhibit particular interest in Telegram Desktop applications running on infected systems. This could indicate that the C2 server may utilize a bespoke Telegram plugin, thereby enabling the malware operator to intercept and manipulate Telegram communications.
Recent Campaigns and Targeting Techniques
In the latter part of May, TA4922 capitalized on tax-related themes to deploy phishing attacks. These emails were written in Chinese and masqueraded as communications from the Shandong Provincial Tax Bureau, compelling recipients to submit required information through a malicious link. This link ultimately led to the download of a ZIP archive containing the initial PackClient executable from an attacker-controlled domain.
By mid-July, the group’s tactics shifted slightly when they impersonated the Indian Income Tax Department through Hindi-language communications. This new approach claimed recipients had underreported their income or failed to disclose foreign assets. Notably, unlike their earlier campaigns, the malicious message delivered a ZIP archive housing an IMG disk image. When mounted, this image contained an executable file and a malware-laden DLL, which exploited DLL sideloading to execute Donut Loader, ultimately paving the way for PackClient installation.
Additionally, Proofpoint discovered that TA4922 deployed ManageEngine remote monitoring and management software hours after the initial infection, indicating a level of sophistication in their post-compromise operations.
While victims of these attacks have primarily been located within Asia, Proofpoint cautions that TA4922 is known for scaling its operations to other global regions, drawing from its historical targeting of countries such as Japan, Singapore, Germany, and the United Kingdom.
Recommendations for Organizations
To guard against the threats posed by TA4922 and similar groups, organizations are encouraged to stay vigilant regarding specific indicators of compromise. This includes monitoring for unique Rundll32 command lines that launch PackClient, keeping an eye on registry entries related to PackClient configurations, analyzing process trees and command line flags, and identifying malware that masquerades as legitimate Windows utilities in temporary directories. Anomalous network traffic over TCP port 6666 may also serve as an important warning signal.
Proofpoint’s findings underscore the evolving nature of cyber threats and emphasize the need for organizations to employ proactive measures to thwart these persistent and sophisticated actors.
