PackClient spyware used in tax-themed phishing

Published September 2, 2026

Chinese attackers sell a remote-control spyware tool called PackClient and use it in fake tax emails to steal data from victims. This spyware lets attackers take over infected computers and spy on users.

Report priority
Medium

How it works

Attackers send fake tax emails with malicious links or attachments that install PackClient spyware when opened.

What to do

If you opened a tax-themed email with a link or attachment from an unknown sender in the past few months, delete any suspicious tax emails immediately.

Scan your computer with trusted antivirus software to check for PackClient spyware. Update your operating system and security tools to protect against new threats.

Technical details

A user gets an email claiming to be from their tax agency with a link or attachment about a tax refund. When they click the link or open the attachment, PackClient spyware secretly installs on their computer. The attackers then use this spyware to watch what the user does, steal files, and even take control of their camera and microphone without them knowing.

Proofpoint found the PackClient RAT sold on Telegram and used by Chinese-speaking TA4922 malware operators in tax-themed phishing attacks.