<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>C2-Framework - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/c2-framework/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 11:39:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/c2-framework/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>TA4922 Deploys PackClient RAT Framework</title><link>https://feed.craftedsignal.io/briefs/2026-08-packclient-ta4922/</link><pubDate>Thu, 27 Aug 2026 11:39:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-packclient-ta4922/</guid><description>The Chinese-speaking threat actor TA4922 is actively using the modular PackClient C2 framework, delivered via tax-themed spearphishing, to conduct surveillance and deploy follow-on tools like ManageEngine RMM.</description><content:encoded><![CDATA[<p>Proofpoint researchers have identified a new, modular command and control (C2) framework dubbed PackClient, currently utilized by the Chinese-speaking threat actor TA4922. The malware is being actively marketed on Telegram and features a sophisticated multi-stage infection chain. Campaigns observed between May and July 2026 targeted organizations in China and India using tax-themed phishing lures that impersonated local tax authorities to pressure victims into executing malicious archives (ZIP/IMG). PackClient is highly modular, supporting data exfiltration, keylogging, and the download of secondary payloads, such as ManageEngine RMM software. The framework employs a unique process tree, including a dedicated &quot;guard&quot; process to ensure the RAT remains active on the victim's host, making it a critical threat to organizations in the targeted regions.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>TA4922 sends spearphishing emails with tax-inspection notices, directing users to download a ZIP archive containing an executable or an IMG disk image.</li>
<li>The user executes a payload or mounts the IMG, initiating a DLL sideloading process (e.g., using a legitimate library like nvdahelperremote.dll).</li>
<li>A Stage 1 loader is executed, which checks for elevated permissions, decrypts an embedded Stage 2 payload, and writes it to disk (e.g., %TEMP%\svchost.exe).</li>
<li>The loader establishes persistence by adding an entry to the HKCU RunOnce registry key.</li>
<li>The Stage 2 &quot;PackClientLauncher&quot; module is executed, which contacts a hardcoded C2 server to download the Stage 3 &quot;PackClientCore&quot; module.</li>
<li>The core module is reflectively loaded into memory and initialized using a configuration found in the .rdata section or registry.</li>
<li>A secondary guard process is spawned with the '--guard' flag to monitor the main process and perform auto-restart if terminated.</li>
<li>The attacker deploys follow-on tools, such as ManageEngine RMM, to maintain persistent remote access and exfiltrate data.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>TA4922 campaigns have targeted government, financial, and enterprise entities in China and India. Successful compromise grants the actor full remote control, including surveillance capabilities, keylogging, and the ability to download arbitrary secondary payloads. This facilitates long-term espionage and unauthorized access to sensitive financial and corporate data.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided Sigma rule to detect the unique PackClient process tree and guard process behavior.</li>
<li>Block the actor-controlled infrastructure domains (gov12366[.]com) and IPs at the organization's perimeter DNS and firewall.</li>
<li>Monitor for unauthorized execution of ManageEngine RMM binaries in environments where they are not officially managed by IT.</li>
<li>Implement restrictive policies on mounting IMG files and executing unsigned binaries from the %TEMP% directory.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>rat</category><category>phishing</category><category>c2-framework</category><category>espionage</category></item></channel></rss>