{
  "id": 3922075,
  "title": "TA4922 PackClient Attacks: From Tax Documents to DLL Side-Loading and RAT Deployment",
  "url": "https://urgent.news/2026/08/28/ta4922-packclient-attacks-from-tax-documents-to-dll-side-loading-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-28T08:14:14.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/ta4922-packclient-attacks-from-tax-documents-to-dll-side-loading-and-rat-deployment-5fid"
  },
  "original_language": "en",
  "account": "The TA4922 PackClient attacks, involving fake tax documents from China and India, employed DLL side-loading and Donut Loader execution to deploy a modular RAT. These attacks, targeting organizations in mainland China and India, utilized emails disguised as tax notices and refunds. The emails directed users to download ZIP archives containing a legitimate executable and a malicious DLL, triggering the DLL side-loading process. The malicious DLL unpacked PackClient into memory and connected to a hard-coded C2 server via a custom TCP protocol. After PackClient execution, additional ManageEngine remote management tools were deployed. The attacks relied on external email senders disguising themselves as tax and regulatory authorities, remote control of compromised endpoints from the attacker's operational infrastructure, and the successful execution of the ZIP/IMG files.",
  "summary": "1. Overview Article Title : Carry-On Compromise: TA4922 Packs PackClient Publisher : Proofpoint Threat Research Publication Date : August 27, 2026 Source : Proofpoint Threat Research Related Source : MITRE ATT&CK - DLL Side-Loading Related Malware / Threat Groups / CVEs / Products : PackClient, Donut Loader, ManageEngine RMM, TA4922, Microsoft Windows Severity : High (Ongoing targeted campaigns…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}