Date: 08/31/2026
Severity: High
Summary
Researchers identified PackClient, a modular command-and-control (C2) framework actively being sold on Telegram. The framework has been linked to at least one Chinese-speaking threat actor, TA4922. PackClient expands TA4922’s arsenal of malware used for gaining initial access to targeted systems. The framework supports data theft, surveillance, and the download of additional plugins and payloads. Its emergence highlights TA4922’s continued use of tools originating from the Chinese-speaking cybercrime ecosystem.
Indicators of Compromise (IOC) List
Domains/URLs | gov12366.com |
IP Address | 64.81.30.99 192.252.180.45 154.36.188.201 192.229.87.219 154.36.188.98 206.238.196.96 |
Hash | 7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a
38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c
7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94
da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293
832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242
83d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2
aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69f
35712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9
109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7
fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "gov12366.com" or url like "gov12366.com" or siteurl like "gov12366.com" |
Detection Query 2 : | dstipaddress IN ("192.252.180.45","206.238.196.96","192.229.87.219","154.36.188.98","64.81.30.99","154.36.188.201") or srcipaddress IN ("192.252.180.45","206.238.196.96","192.229.87.219","154.36.188.98","64.81.30.99","154.36.188.201") |
Detection Query 3 : | sha256hash IN ("7108ff29916d064216aa2ece7fb395f1e3a73d12d19895bffc0bd46806cbf85a","fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53","38ec1f5e23f65b10ae3027beabfa0bf7f9fb686355a9e33c7e7e44e6a998e04c","7295090c2cb63ebc43f932451971c41f9d015d2741e97ae3d9855f5ae87cff94","da90b1219dcf1bf23e604b182b7737e188825df7205ea7b172231de66aeba293","832e68e12ebf62b60cfe2a7b45e5948fcc364a74c8d73c3748b267617bcfb242","83d16cd963b1926a9967e6928340f099abf983ca496639cfddd9d63e327db3d2","aa8cda8a9a7835a72d1b832985c5976873d2c6e791524039b809ce4441d3f69f","35712dc8aa497371ce48a36975781dfc3a120ce5c99dc209637b05751bf4e8e9","109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7")
|
Reference:
https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient