Research & KnowledgeEvent: August 31, 2026
Proofpoint observed a Chinese-speaking threat actor using a C2 framework called PackClient to target organizations in Asia, including tax-themed lures impersonating the Shandong Provincial Tax Bureau and the Government of India Income Tax Department.
Published
Signal category
Research & Knowledge
Quote
“Threat researchers at Proofpoint have observed a Chinese-speaking threat actor (TA4922) using a C2 framework that enables data theft, surveillance, and downloading of additional plugins/payloads.”
— Brittany Vaught|Proofpoint team
Company
- Industry
- Computer and Network Security
- Location
- Sunnyvale, US
- Company size
- 5,261 employees
Intent-based protection for every human and every AI agent, across all data.