Summary
A new advanced Remote Access Trojan (RAT) called PackClient is being sold on Telegram and used by the financially motivated hacking group TA4922 to target organizations in China and India through spoofed tax authority emails. Proofpoint researchers warn that the malware's advanced capabilities make it likely to be adopted by more threat actors globally.