Proofpoint researchers recently discovered a RAT framework we named PackClient. PackClient is a full featured, modular command and control (C2) framework that supports data theft, surveillance, and downloading of additional plugins and payloads.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
PackClient in ATT&CK
23 distinct techniquesTechniques
23 techniques T1204.002 Malicious File T1053.005 Scheduled Task T1055.012 Process Hollowing T1036.005 Match Legitimate Resource Name or Location T1566.001 Spearphishing Attachment T1571 Non-Standard Port T1008 Fallback Channels T1218.011 Rundll32 T1620 Reflective Code Loading T1113 Screen Capture T1095 Non-Application Layer Protocol T1082 System Information Discovery T1090 Proxy T1083 File and Directory Discovery T1057 Process Discovery T1125 Video Capture T1115 Clipboard Data T1059.003 Windows Command Shell T1547.001 Registry Run Keys / Startup Folder T1566.002 Spearphishing Link T1105 Ingress Tool Transfer T1056.001 Keylogging T1219 Remote Access Tools