Proofpoint identified PackClient, a modular C2 framework and RAT sold on Telegram that is being used by TA4922 in tax-themed campaigns targeting organizations in mainland China and India. The malware supports data theft, surveillance, payload delivery, and multiple plugins, and its infrastructure and infection chain include distinct registry paths, process trees, and TCP-based C2 communications. #PackClient #TA4922 #Telegram #RejettoHTTPFileServer #ManageEngine
Keypoints
- Proofpoint discovered PackClient, a full-featured modular RAT/C2 framework sold on Telegram.
- TA4922 is confirmed as at least one user of PackClient in active campaigns.
- Initial attacks used tax-inspection lures impersonating the Shandong Provincial Tax Bureau in mainland China.
- Later campaigns targeted India with Hindi-language tax enforcement and penalty lures impersonating the Indian Income Tax Department.
- PackClient uses a multi-stage infection chain with loaders, DLL sideloading, registry persistence, and reflective loading.
- The core module supports more than 60 commands, including keylogging, screen capture, proxying, browser and process enumeration, and plugin installation.
- Observed infrastructure includes attacker-controlled domains, HTTP file hosting, and custom TCP C2 traffic on ports such as 6666.
MITRE Techniques
- [T1566.001 ] Spearphishing Attachment â Delivered ZIP/IMG attachments via tax-themed email lures to get victims to open malicious files (âclick a link to review documentationâ and âattached tax documents contained within a ZIP archiveâ).
- [T1204.002 ] User Execution: Malicious File â Victims were induced to open downloaded archives and executables to start the infection chain (âthe archive contained an executableâ and âWhen mounted, the image contained an executableâ).
- [T1105 ] Ingress Tool Transfer â Malware downloaded next-stage payloads and plugins from C2 infrastructure (âdownloads the next stage of the chainâ and âdownloaded another executable payloadâ).
- [T1055 ] Process Injection / Reflective Loading â The launcher reflectively loaded the core RAT DLL into memory (âreflectively loads this PE file into memoryâ).
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder â Persistence was set through registry autorun entries (âreg add HKCUâŚRunOnceâ).
- [T1574.002 ] Hijack Execution Flow: DLL Side-Loading â An IMG file contained a malicious DLL used to execute the loader (âleveraged DLL sideloading to execute Donut Loaderâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Plugin functionality includes creating scheduled tasks (âsystem administration type activities such as process listing, creating scheduled tasksâ).
- [T1027 ] Obfuscated Files or Information â Packets and payloads used encrypted/XOR-decrypted content and encoded delivery (âXOR-decrypts the Stage 2 payloadâ and âbase-64 encoded binary dataâ).
- [T1082 ] System Information Discovery â The malware collected OS version, machine GUID, local IP, architecture, and related system data (âthe rest of the TCP frame contains system informationâ).
- [T1057 ] Process Discovery â It enumerated running processes, including security tools and browsers (âEnumerates running processes and reports on processes such as security productsâ).
- [T1056.001 ] Keylogging â PackClient includes keylogger capabilities (âKeylogger and clipper capabilitiesâ and âstart the keyloggerâ).
- [T1113 ] Screen Capture â The C2 can request screenshots/desktop previews (âStart screen captureâ and âEnables desktop screenshot thumbnail functionalityâ).
- [T1219 ] Remote Access Software â The framework includes remote desktop, terminal, webcam, and proxy features (âSupport for remote desktop screen sharingâ and âInteractive remote shellâ).
- [T1090.001 ] Proxy: Internal Proxy â The malware can create SOCKS/TCP tunnels (âStart a proxy/SOCKS tunnelâ and âSOCKS/TCP proxy tunnelingâ).
- [T1041 ] Exfiltration Over C2 Channel â Stolen data such as screenshots and keylogger output was sent to the C2 (âsync keylogger dataâ and desktop screenshot transmission).
Indicators of Compromise
- [IP address and port ] C2 / payload hosting infrastructure â 154.36.188[.]98:8080, 206.238.196[.]96:6666
- [IP address ] Post-infection / C2 infrastructure â 64[.]81[.]30[.]99, 154.36.188[.]201
- [IP address and port ] Additional C2 communications â 192[.]252[.]180[.]45:6666
- [Domain ] Attacker-controlled domain â gov12366[.]com
- [File names ] Delivery and payload files â ć°ćŽčľć.zip, čľćć°ćŽ[.]exe, Tax_Notice_23665.zip, Tax_Notice_23665.img
- [File names ] Later lure attachments and loader components â ITDTAX202601987.zip, Tax_Notice_23709.img, Tax_Notice_00481.img, nvdahelperremote.dll
- [File hashes ] ZIP/IMG and payload hashes â 109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7, fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53
- [File hashes ] Additional attachment and DLL hashes â 7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a, 7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94, and 4 more hashes
Read more: https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient