From Launcher to recovered Core: A technical teardown of PackClient’s PLK1 delivery, plugin loading, screen-capture paths, persistence, and historical C2 traffic.
Read the Publication · Download the PDF
- Reconstruction of the worker-side
1RCPinterface: a 20-byte header, four message types, and top-down BGRX framebuffer data. - Recovered transport and authentication contracts: outer framing, the handshake, HMAC verification before AES-CBC decryption, and the PLK1 cache-validation path.
- Recovered a 985,088-byte x86
PackClientCore.dlldirectly from historical PLK1 traffic. - Reassembled a complete historical
PLH1 -> PLC1 -> PLA1 -> PLK1session, followed by bidirectional Core traffic and 15PV10JPEG frames. - Identified the signed host’s carrier export, the injected Donut package and terminal-loader ABI, the Core’s modern and legacy plugin-loading contracts, and its built-in
PV10producer. - Mapped all 11 Core exports, the Launcher-to-Core ABI, six local settings, the Core-specific type-
0x16encryption layer, staged plugin delivery and cache logic, DPAPI-protected Core-update storage, ETCHOOK clipboard replacement, and the main command handlers. - Runtime separation of two persistence paths: normal full-EXE execution persists
Tax_Notice_23665.exe, while direct-DLL execution produces a brokenrundll32.exetask without the original DLL argument.
flowchart TD
H["Signed NVDA Host<br/>Tax_Notice_23665.exe"]
C["Carrier DLL<br/>nvdaHelperRemote.dll"]
V["Suspended 32-bit Surrogate<br/>SysWOW64\\svchost.exe"]
D["Injected Donut Package<br/>exact x86 loader + embedded A"]
subgraph P[" "]
A["Executable A<br/>Wrapper / Mapper"]
B["Executable B<br/>PackClientLauncher.exe"]
A -->|"maps embedded PE"| B
end
H -->|"DLL sideload"| C
C -->|"creates suspended process<br/>remote placement + context hijack"| V
V -->|"call-over-data entry"| D
D -->|"maps and starts"| A
B --> T["Transport + Authentication<br/>PLH1 / PLC1 / PLA1"]
B --> K["PLK1 Delivery + Cache"]
B --> S["Active-session Handoff"]
B --> R["1RCP Screenshot Worker"]
K -->|"raw LZ4 + SHA-256 validation"| CORE["PackClientCore.dll<br/>985,088-byte x86 DLL"]
CORE --> PABI["Plugin ABI + Legacy Main Loader"]
CORE --> PV10["GDI/WIC PV10 JPEG Producer"]
R -. "pre-existing local endpoint" .-> PEER["External 1RCP Peer<br/>(Unrecovered)"]
| Topic | Reference |
|---|---|
| Execution chain and recovered components | Launcher Architecture |
1RCP screenshot protocol and framebuffer |
Screenshot IPC |
| Benign local peer/simulator | Synthetic IPC Validation |
| Network framing, authentication and PLK1 | Launcher Protocol |
| Core recovery and runtime behavior | Core Analysis |
| Windows session handoff | Active-session Handoff |
| Runtime memory, persistence and networking | Runtime Analysis |
| Evidence, identities and scope | Evidence |
| Known gaps and limitations | Limitations |
| Passive protocol-analysis tools | Tooling |
| Detection engineering | Detection Guide |
| Interface | Purpose |
|---|---|
tools/packclient_decode.py |
Decode supplied raw streams into structured JSON |
tools/packclient_pcap_decode.py |
Decode supplied PCAP/PCAPNG into per-flow timelines |
tools/wireshark/packclient.lua |
Display protocol metadata in Wireshark/TShark |
The Python CLIs require Python 3.11–3.13 and the standard library. LZ4 support and detection-engine tests have separate pinned optional dependencies. The quickstart creates a deterministic synthetic input without any malware.
python -B -m unittest discover -s tests -vThe optional synthetic IPC kit exercises the reconstructed 1RCP contract using benign deterministic inputs and outputs, without malware or desktop capture.
The Sigma, Suricata and YARA rules are included as experimental detection candidates with regression coverage. Production accuracy has not been measured.
The available evidence does not identify the external 1RCP peer, contain a delivered plugin binary, prove a bridge between 1RCP and Core PV10, recover the server implementation, establish a complete real 1RCP exchange, or prove the causal diagnosis of the worker failure.
Additional limitations are documented in Limitations.
PackClient was previously documented by Proofpoint and Deception.Pro. This work adds implementation details from the analyzed carrier and Launcher, and recovered Core. See Prior Work for more details.
Use CITATION.cff to cite the report.
Updated publication date: 9 September 2026.

