New Delhi, Aug. 28 -- A Chinese-speaking threat actor has expanded its activity to India, using Hindi-language phishing emails impersonating the Income Tax Department to target organisations, according to threat research from Proofpoint. The campaigns, observed in July 2026, used fake tax notices, penalty demands and threats of legal action to trick recipients into opening malicious attachments that delivered the PackClient malware framework.

Proofpoint said the activity was linked to TA4922, a threat actor first observed in May targeting organisations with operations in mainland China. The group conducted at least two campaigns against Indian organisations in July, marking a geographic expansion of its activity.

The attacks relied on f...