A tax notice that leads you to run a Windows program can open a remote-access incident that survives closing one process. Proofpoint’s August 27 research describes TA4922 delivering PackClient through tax-themed messages targeting organizations in China and India. The observed delivery included ZIP archives, with Indian campaigns also using an IMG disk image and DLL sideloading. PackClient has modular remote-control capabilities and a guard process that can restart its core. [1]
If you ran a file from that kind of unexpected attachment, stop using the computer for sensitive logins. On a work device, contact IT through an independently known channel and follow its containment process. Preserve the original message and what you opened; do not forward an executable to colleagues as a warning.
A document request should not become program execution

This is a fictional educational example, not a recovered campaign message:
From: Tax review desk <notice@[sender-domain]>
Subject: Urgent tax-document review
Your business must review the attached notice within 72 hours. Open the document package to respond and avoid a penalty.
Attachment: Tax_Notice_[reference].zip
The pressure is the point: an unfamiliar sender presents a deadline and a penalty to make execution feel like routine paperwork. Verify a tax request through the authority’s independently located official service or your established adviser. Do not use contact details supplied only by the message.
| What happened | Response boundary |
|---|---|
| You received the email | Report the lure. Receipt alone does not establish PackClient execution. |
| You downloaded or opened the archive | Stop before launching anything inside. Record whether a disk image was mounted or any program actually ran. |
| You ran the attached program or a security alert appeared | Preserve the alert and isolate according to your incident process. A familiar filename or document icon does not settle what executed. |
| You see a new remote-management application | Ask IT to verify its enrollment, server and installation history. Do not approve its access merely because the binary is signed. |
Why ending one process is not a cleanup result

Proofpoint’s process tree illustrates the guard relationship. Names such as svchost.exe also belong to legitimate Windows components, so a name alone is not a removal instruction. Analysts need the parent process, full path, command line and surrounding execution history. [1]
For a home PC where the attachment ran, a complete malware scan is useful because deleting the initial download may leave a loader, persistence or another module. Download Gridinsoft Anti-Malware from its official site, update it and run a full scan; review and quarantine detections. A scan supports cleanup but cannot prove what an operator already viewed or copied.
If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.
Scan the Windows PCIf suspicious activity returns after quarantine or reboot, preserve the new evidence and escalate. Do not repeatedly restore a detected file to test the original email. On a managed device, let the response team choose tooling and evidence-preservation steps.
A signed management agent can still be unauthorized
In a controlled honeynet observation associated with this research, Deception.Pro documented an operator installing a genuine ManageEngine agent configured for an attacker-controlled server. That is an observed abuse of legitimate administration software, not a claim that every installation of the product is malicious. [2]
The practical check is who enrolled the agent, when it arrived and which management server it trusts. Compare those facts with your organization’s approved deployment. Removing the first RAT without addressing an unauthorized second access path can leave the incident unresolved.
Recover accounts after containing the computer
Use a clean device to change exposed passwords, revoke unfamiliar sessions and review important account activity. Tell the response team which accounts were used after the suspected execution. Do not assume every optional PackClient capability ran, but do not equate a quiet screen with the absence of remote access.
Keep the message, attachment names, execution time, detection details and any unexpected management-agent installation together. This gives an investigator a coherent sequence instead of a collection of unrelated screenshots.
References
- Cucci K., Kinner R., Robinson T., Proofpoint Threat Research. PackClient delivery and technical analysis. August 27, 2026.
- MalBeacon, Deception.Pro. PackClient operational observation in a controlled honeynet. August 27, 2026.

