Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
schtasks /Create /TN NvSvc ... /SC ONLOGON /RL HIGHEST pointing at C:\ProgramData\NVIDIA Corporation\NvSvc\Tax_Notice_10029.exe.
schtasks /Create /TN NvSvc ... /SC ONLOGON /RL HIGHEST pointing at C:\ProgramData\NVIDIA Corporation\NvSvc\Tax_Notice_10029.exe.
NvSvc points to C:\ProgramData\NVIDIA Corporation\NvSvc\Tax_Notice_10029.exe.
The dropper spawns an argument-less C:\Windows\SysWOW64\svchost.exe that immediately connects to 192[.]252[.]180[.]45:6666.
PackClient enumerates running processes, including security products, messaging applications, and browsers; its C2 also supports Q|PROC|LIST.
The core module has keylogger capabilities and C2 commands to start, stop, and synchronize keylogger data; offline keylogging is also supported.
The client transmits a thumbnail-sized desktop screenshot to C2; supported commands include SCR and SCR|PREVIEW|REQ.
A failed lookup for xzz[.]cam is seen from the hollowed svchost process.
The PXY command starts a proxy/SOCKS tunnel, and PackPlugin.Proxy.dll supports SOCKS/TCP proxy tunneling.
PackClient connects to hardcoded C2 endpoints over raw TCP sockets, including observed communications over TCP port 6666 using a custom protocol.
The initial PackClient executable downloads an encrypted second-stage payload, while PackClientLauncher downloads the core RAT DLL and later receives plugins or payloads from C2.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular remote-access trojan delivered as Tax_Notice_10029.exe from a mounted tax-return-themed disk image. It establishes a custom TCP C2 channel on port 6666, persists through an ONLOGON scheduled task masquerading as an NVIDIA service, uses process hollowing of SysWOW64\svchost.exe, and enabled later operator deployment of an attacker-controlled ManageEngine Endpoint Central agent.
A modular remote-access trojan and C2 framework sold through Telegram and used by TA4922. It uses staged loaders, registry persistence, a guard process for process resurrection, dual C2 connections, and reflectively loaded core and plugin modules. It supports over 60 commands for shell execution, file and registry operations, process discovery, screenshots/remote desktop, webcam capture, SOCKS proxying, keylogging, clipboard theft, browser-data theft, payload delivery, and possible Telegram interception.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.