securityonline.info 9/2/2026, 7:16:13 AM · external

PackClient RAT: New C2 Framework Sold on Telegram

PackClient RAT: New C2 Framework Sold on Telegram

A recent security alert has identified a new remote access trojan (RAT) called PackClient, linked to the Chinese-speaking threat actor TA4922. This malware is being distributed through tax-themed phishing emails targeting organizations mainly in China and India. The PackClient framework allows operators to perform data theft, keylogging, screen capture, and other surveillance tasks. It is modular, consisting of a loader, core module, and plugins that enhance its capabilities.

The infection chain involves downloading malicious files via ZIP attachments, which contain executables to install the malware. Once active, PackClient communicates with multiple command and control servers to execute commands and exfiltrate stolen data, which includes screenshots and keystrokes. Security experts recommend caution with tax notices and advise blocking specific file types to prevent infection.

View full article

Article by CyberSIXT