A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting organizations in mainland China and India. The activity, observed by Proofpoint in May and July 2026, demonstrates the group’s expanding initial-access capabilities and the increasing availability of sophisticated malware on Chinese-language Telegram marketplaces. PackClient is a […]
Read the original article: