Carry-On Compromise: TA4922 Packs PackClient

    Date: 08/31/2026

    Severity: High 

    Summary

    Researchers identified PackClient, a modular command-and-control (C2) framework actively being sold on Telegram. The framework has been linked to at least one Chinese-speaking threat actor, TA4922. PackClient expands TA4922’s arsenal of malware used for gaining initial access to targeted systems. The framework supports data theft, surveillance, and the download of additional plugins and payloads. Its emergence highlights TA4922’s continued use of tools originating from the Chinese-speaking cybercrime ecosystem.

    Indicators of Compromise (IOC) List 

    Domains/URLs

    gov12366.com

    IP Address 

    64.81.30.99

    192.252.180.45

    154.36.188.201

    192.229.87.219

    154.36.188.98

    206.238.196.96

    Hash 

    7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a

    38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c

    7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94

    da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293

    832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242

    83d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2

    aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69f

    35712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9

    109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7

    fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "gov12366.com" or url like "gov12366.com" or siteurl like "gov12366.com"

    Detection Query 2 :

    dstipaddress IN ("192.252.180.45","206.238.196.96","192.229.87.219","154.36.188.98","64.81.30.99","154.36.188.201") or srcipaddress IN ("192.252.180.45","206.238.196.96","192.229.87.219","154.36.188.98","64.81.30.99","154.36.188.201")

    Detection Query 3 :

    sha256hash IN ("7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a","fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53","38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c","7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94","da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293","832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242","83d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2","aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69f","35712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9","109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7")

    Reference:    

    https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient                             


    Tags

    MalwareThreat ActorChinaTelegramCredential Harvesting

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags