{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/c2-framework/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["TA4922"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Remote Monitoring and Management"],"_cs_severities":["high"],"_cs_tags":["rat","phishing","c2-framework","espionage"],"_cs_type":"threat","_cs_vendors":["ManageEngine"],"content_html":"\u003cp\u003eProofpoint researchers have identified a new, modular command and control (C2) framework dubbed PackClient, currently utilized by the Chinese-speaking threat actor TA4922. The malware is being actively marketed on Telegram and features a sophisticated multi-stage infection chain. Campaigns observed between May and July 2026 targeted organizations in China and India using tax-themed phishing lures that impersonated local tax authorities to pressure victims into executing malicious archives (ZIP/IMG). PackClient is highly modular, supporting data exfiltration, keylogging, and the download of secondary payloads, such as ManageEngine RMM software. The framework employs a unique process tree, including a dedicated \u0026quot;guard\u0026quot; process to ensure the RAT remains active on the victim's host, making it a critical threat to organizations in the targeted regions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eTA4922 sends spearphishing emails with tax-inspection notices, directing users to download a ZIP archive containing an executable or an IMG disk image.\u003c/li\u003e\n\u003cli\u003eThe user executes a payload or mounts the IMG, initiating a DLL sideloading process (e.g., using a legitimate library like nvdahelperremote.dll).\u003c/li\u003e\n\u003cli\u003eA Stage 1 loader is executed, which checks for elevated permissions, decrypts an embedded Stage 2 payload, and writes it to disk (e.g., %TEMP%\\svchost.exe).\u003c/li\u003e\n\u003cli\u003eThe loader establishes persistence by adding an entry to the HKCU RunOnce registry key.\u003c/li\u003e\n\u003cli\u003eThe Stage 2 \u0026quot;PackClientLauncher\u0026quot; module is executed, which contacts a hardcoded C2 server to download the Stage 3 \u0026quot;PackClientCore\u0026quot; module.\u003c/li\u003e\n\u003cli\u003eThe core module is reflectively loaded into memory and initialized using a configuration found in the .rdata section or registry.\u003c/li\u003e\n\u003cli\u003eA secondary guard process is spawned with the '--guard' flag to monitor the main process and perform auto-restart if terminated.\u003c/li\u003e\n\u003cli\u003eThe attacker deploys follow-on tools, such as ManageEngine RMM, to maintain persistent remote access and exfiltrate data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eTA4922 campaigns have targeted government, financial, and enterprise entities in China and India. Successful compromise grants the actor full remote control, including surveillance capabilities, keylogging, and the ability to download arbitrary secondary payloads. This facilitates long-term espionage and unauthorized access to sensitive financial and corporate data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect the unique PackClient process tree and guard process behavior.\u003c/li\u003e\n\u003cli\u003eBlock the actor-controlled infrastructure domains (gov12366[.]com) and IPs at the organization's perimeter DNS and firewall.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized execution of ManageEngine RMM binaries in environments where they are not officially managed by IT.\u003c/li\u003e\n\u003cli\u003eImplement restrictive policies on mounting IMG files and executing unsigned binaries from the %TEMP% directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T11:39:31Z","date_published":"2026-08-27T11:39:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-packclient-ta4922/","summary":"The Chinese-speaking threat actor TA4922 is actively using the modular PackClient C2 framework, delivered via tax-themed spearphishing, to conduct surveillance and deploy follow-on tools like ManageEngine RMM.","title":"TA4922 Deploys PackClient RAT Framework","url":"https://feed.craftedsignal.io/briefs/2026-08-packclient-ta4922/"}],"language":"en","title":"CraftedSignal Threat Feed - C2-Framework","version":"https://jsonfeed.org/version/1.1"}