Carry-On Compromise: TA4922 Packs PackClient

Carry-On Compromise: TA4922 Packs PackClient
Proofpoint identified PackClient, a modular C2 framework and RAT sold on Telegram that is being used by TA4922 in tax-themed campaigns targeting organizations in mainland China and India. The malware supports data theft, surveillance, payload delivery, and multiple plugins, and its infrastructure and infection chain include distinct registry paths, process trees, and TCP-based C2 communications. #PackClient #TA4922 #Telegram #RejettoHTTPFileServer #ManageEngine

Keypoints

  • Proofpoint discovered PackClient, a full-featured modular RAT/C2 framework sold on Telegram.
  • TA4922 is confirmed as at least one user of PackClient in active campaigns.
  • Initial attacks used tax-inspection lures impersonating the Shandong Provincial Tax Bureau in mainland China.
  • Later campaigns targeted India with Hindi-language tax enforcement and penalty lures impersonating the Indian Income Tax Department.
  • PackClient uses a multi-stage infection chain with loaders, DLL sideloading, registry persistence, and reflective loading.
  • The core module supports more than 60 commands, including keylogging, screen capture, proxying, browser and process enumeration, and plugin installation.
  • Observed infrastructure includes attacker-controlled domains, HTTP file hosting, and custom TCP C2 traffic on ports such as 6666.

MITRE Techniques

  • [T1566.001 ] Spearphishing Attachment – Delivered ZIP/IMG attachments via tax-themed email lures to get victims to open malicious files (‘click a link to review documentation’ and ‘attached tax documents contained within a ZIP archive’).
  • [T1204.002 ] User Execution: Malicious File – Victims were induced to open downloaded archives and executables to start the infection chain (‘the archive contained an executable’ and ‘When mounted, the image contained an executable’).
  • [T1105 ] Ingress Tool Transfer – Malware downloaded next-stage payloads and plugins from C2 infrastructure (‘downloads the next stage of the chain’ and ‘downloaded another executable payload’).
  • [T1055 ] Process Injection / Reflective Loading – The launcher reflectively loaded the core RAT DLL into memory (‘reflectively loads this PE file into memory’).
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder – Persistence was set through registry autorun entries (‘reg add HKCU…RunOnce’).
  • [T1574.002 ] Hijack Execution Flow: DLL Side-Loading – An IMG file contained a malicious DLL used to execute the loader (‘leveraged DLL sideloading to execute Donut Loader’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Plugin functionality includes creating scheduled tasks (‘system administration type activities such as process listing, creating scheduled tasks’).
  • [T1027 ] Obfuscated Files or Information – Packets and payloads used encrypted/XOR-decrypted content and encoded delivery (‘XOR-decrypts the Stage 2 payload’ and ‘base-64 encoded binary data’).
  • [T1082 ] System Information Discovery – The malware collected OS version, machine GUID, local IP, architecture, and related system data (‘the rest of the TCP frame contains system information’).
  • [T1057 ] Process Discovery – It enumerated running processes, including security tools and browsers (‘Enumerates running processes and reports on processes such as security products’).
  • [T1056.001 ] Keylogging – PackClient includes keylogger capabilities (‘Keylogger and clipper capabilities’ and ‘start the keylogger’).
  • [T1113 ] Screen Capture – The C2 can request screenshots/desktop previews (‘Start screen capture’ and ‘Enables desktop screenshot thumbnail functionality’).
  • [T1219 ] Remote Access Software – The framework includes remote desktop, terminal, webcam, and proxy features (‘Support for remote desktop screen sharing’ and ‘Interactive remote shell’).
  • [T1090.001 ] Proxy: Internal Proxy – The malware can create SOCKS/TCP tunnels (‘Start a proxy/SOCKS tunnel’ and ‘SOCKS/TCP proxy tunneling’).
  • [T1041 ] Exfiltration Over C2 Channel – Stolen data such as screenshots and keylogger output was sent to the C2 (‘sync keylogger data’ and desktop screenshot transmission).

Indicators of Compromise

  • [IP address and port ] C2 / payload hosting infrastructure – 154.36.188[.]98:8080, 206.238.196[.]96:6666
  • [IP address ] Post-infection / C2 infrastructure – 64[.]81[.]30[.]99, 154.36.188[.]201
  • [IP address and port ] Additional C2 communications – 192[.]252[.]180[.]45:6666
  • [Domain ] Attacker-controlled domain – gov12366[.]com
  • [File names ] Delivery and payload files – 数据资料.zip, 资料数据[.]exe, Tax_Notice_23665.zip, Tax_Notice_23665.img
  • [File names ] Later lure attachments and loader components – ITDTAX202601987.zip, Tax_Notice_23709.img, Tax_Notice_00481.img, nvdahelperremote.dll
  • [File hashes ] ZIP/IMG and payload hashes – 109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7, fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53
  • [File hashes ] Additional attachment and DLL hashes – 7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a, 7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94, and 4 more hashes


Read more: https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient