Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures
The Chinese are using a tax lure to deploy a new RAT and take over victim devices.
A new malware called PackClient is circulating globally through tax audit lures, according to security researchers at Proofpoint. The RAT, or Remote Access Trojan, is being actively sold on Telegram and has been used in recent attacks on organizations in China and India. PackClient is a sophisticated tool that can steal files, execute remote shells, capture screens, manage desktops, access webcams, log keystrokes, escalate privileges, and perform system administration tasks.
While originally used by the financially motivated hacking group TA4922, its advanced capabilities may attract other threat actors to utilize it in future campaigns. The emails used in the attacks spoofed local tax authorities, claiming that recipients needed to conduct a "self-inspection" and download paperwork attached to the message.
In reality, the "paperwork" was the PackClient installer. Proofpoint did not disclose the number of organizations affected or the specific industries targeted. However, previous reports suggest that TA4922 typically targets small and medium-sized organizations, primarily in Japan, Taiwan, Korea, Singapore, India, and recently, European and UK organizations.
Proofpoint warns that the widespread availability of PackClient through Telegram could lead to broader adoption and deployment against more organizations, especially in the western part of the world.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.