TI Mindmap HUB
Threat Intelligence Report

[Op Report] PackClient: Hands-on-Keyboard with a new C2 Framework

📅 August 27, 2026 📰 blog.deception.pro 🔍 0 CVE(s) referenced

A Chinese-speaking threat actor used the new PackClient RAT for initial access, then covertly leveraged a legitimate, vendor-signed endpoint management platform (ManageEngine Endpoint Central) to gain persistent, full-spectrum control over a critical infrastructure consultancy's network—demonstrating a stealthy handoff from commodity malware to trusted IT tools for deep post-compromise operations.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle