Key Findings
- Proofpoint identified a command and control (C2) framework called PackClient sold on Telegram.
- It is being used by at least one threat actor, Chinese-speaking TA4922.
- With this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem.
![]()
Carry-On Compromise: TA4922 Packs PackClient | Proofpoint US
Key Findings Proofpoint identified a command and control (C2) framework called PackClient sold on Telegram. It is being used by at least one threat actor, Chinese-speaking TA4922. Withwww.proofpoint.com