TA4922 Uses Fake Tax Notices to Deploy PackClient RAT via DLL Side-Loading
Threat actor TA4922 has been running targeted email campaigns since late May 2026, impersonating tax authorities in China and India to trick recipients into downloading malicious ZIP or IMG archives. The attack chain relies on DLL side-loading, where a legitimate executable loads a malicious DLL, triggering Donut Loader to inject the modular remote access trojan PackClient directly into memory. PackClient communicates with hard-coded command-and-control servers over a custom TCP protocol, including port 6666, enabling screen capture, keylogging, and process monitoring. In campaigns observed between July 20 and 22, 2026, attackers also deployed ManageEngine remote management tools on compromised endpoints for persistent access. Security researchers from Proofpoint recommend blocking tax-themed archive attachments at email gateways, detecting DLL side-loading from user-writable directories, and monitoring unknown outbound TCP connections.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in