2026-08-28 · view entry permalink →
TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit — dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India
Proofpoint documents PackClient, a modular remote-access trojan and command-and-control framework actively sold on Telegram, now in use by TA4922 — a China-nexus, financially-motivated cluster this pipeline already tracks (registry actor:ta4922, first seen 2026-06-05, previously associated with Atlas RAT, RomulusLoader and SilentRunLoader, and separately noted by this pipeline as expanding into DE/UK/IT): "with this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem" (Proofpoint, 2026-08-27).
PackClient's delivery chain uses rundll32 execution and reflective DLL loading, with persistence via a registry RunOnce key, and stores its configuration under HKCU\SOFTWARE\PackClientConsole: "distinct Rundll32 command line used to launch PackClient. PackClient config stored in registry (HKCU\SOFTWARE\PackClientConsole\). Distinct process tree and command line flags" (Proofpoint, 2026-08-27). It supports keylogging, webcam and screen capture, file exfiltration and plugin/payload management over dual C2 channels using a custom TCP protocol with distinctive handshake byte sequences (Proofpoint names them PLH1/PLC1): "PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads" (Proofpoint, 2026-08-27).
In the observed campaigns TA4922 used tax-themed phishing lures against organisations in mainland China and India, with post-compromise activity that included deploying ManageEngine remote-monitoring-and-management tooling — a legitimate RMM abused for continued access, consistent with this actor's established pattern of using commodity or legitimate management tools post-compromise. Proofpoint does not name a MITRE ATT&CK technique explicitly, but the described behaviours map to registry Run-key persistence, DLL side-loading/reflective loading defence evasion, and collection via keylogging and screen capture.
The campaign targeting is mainland China and India, not this constituency's home region or profiled sectors directly, but the relevance rests on two points: TA4922 is separately tracked by this pipeline as expanding tooling and targeting into Germany, the UK and Italy, so a new Telegram-proliferated C2 framework in this actor's toolkit is transferable tradecraft to watch for; and a MaaS tool sold on Telegram is not exclusive to one actor and may surface again against a different, more directly-relevant target set. Triage: a registry key at HKCU\SOFTWARE\PackClientConsole on any endpoint has no legitimate application association and is a direct compromise indicator; process trees showing rundll32 launched with non-standard command-line flags followed by reflective DLL-loading behaviour (no corresponding file on disk for the loaded module) are the discriminator against ordinary rundll32 usage, which normally loads a named, on-disk DLL export.
With this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem.
PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads.
Distinct Rundll32 command line used to launch PackClient. PackClient config stored in registry (HKCU\\SOFTWARE\\PackClientConsole\\). Distinct process tree and command line flags.