Reconstruction of PackClient's launcher, PLK1 delivery, recovered Core, plugin-loading contracts, screenshot paths, persistence, and historical network behavior.
Read the Publication · Download the PDF
- Reconstruction of the worker-side
1RCPinterface: a 20-byte header, four message types, top-down BGRX framebuffer data, and an external endpoint peer. - Recovered transport and authentication contracts: outer framing, handshake, authenticated AES-CBC receive ordering, and the PLK1 cache acceptance path.
- Byte-exact recovery of a 985,088-byte x86
PackClientCore.dllfrom eight complete historical PLK1 transfers, with matching plaintext and mapped-.textidentities. - Historical successful protocol progression through
PLH1 -> PLC1 -> PLA1 -> PLK1, followed by bidirectional Core traffic and 15PV10JPEG frames. - Independent recovery of the signed host's invoked carrier export, the injected Donut package and terminal-loader ABI, the Core's modern and legacy plugin-loading contracts, and its built-in
PV10producer. - Core closure includes all exports, the Launcher ABI, six local configuration keys, phase-specific application encryption, staged plugin/update storage, ETCHOOK clipboard replacement, and the major command/subsystem census.
- Runtime separation of the normal full-EXE persistence path from the direct-DLL
rundll32sandbox artifact; no second PackClient variant was established.
flowchart TD
H["Signed NVDA Host<br/>Tax_Notice_23665.exe"]
C["Carrier DLL<br/>nvdaHelperRemote.dll"]
V["Suspended 32-bit surrogate<br/>SysWOW64\\svchost.exe"]
D["Injected Donut package<br/>exact x86 loader + embedded A"]
subgraph P[" "]
A["Executable A<br/>Wrapper / Mapper"]
B["Executable B<br/>PackClientLauncher.exe"]
A -->|"maps embedded PE"| B
end
H -->|"DLL sideload"| C
C -->|"creates suspended process<br/>remote placement + context hijack"| V
V -->|"call-over-data entry"| D
D -->|"maps and starts"| A
B --> T["Transport + Authentication<br/>PLH1 / PLC1 / PLA1"]
B --> K["PLK1 Delivery + Cache"]
B --> S["Active-session Handoff"]
B --> R["1RCP Screenshot Worker"]
K -->|"8 verified PLK1 transfers"| CORE["PackClientCore.dll<br/>985,088-byte x86 DLL"]
CORE --> PABI["Plugin ABI + legacy Main loader"]
CORE --> PV10["GDI/WIC PV10 JPEG producer"]
R -. "pre-existing local endpoint" .-> PEER["External 1RCP Peer<br/>Unrecovered"]
| Topic | Reference |
|---|---|
| Host, carrier, package and recovered components | Architecture |
1RCP screenshot protocol and framebuffer |
Screenshot IPC |
| Benign local peer/simulator | Synthetic IPC validation |
| Framing, handshake, encryption and PLK1 | Protocol |
| Historical artifacts, recovered Core and plugin boundaries | Core and artifact audit |
| Token selection and session drift | Active-session Handoff |
| Runtime memory, persistence and network observations | Runtime |
| Artifact identities and claim boundaries | Evidence |
| Research limitations | Limitations |
| Passive decoders | Tooling |
| Detection candidates | Detection Guide |
| Interface | Purpose |
|---|---|
tools/packclient_decode.py |
Decode supplied raw streams into structured JSON |
tools/packclient_pcap_decode.py |
Decode supplied PCAP/PCAPNG into per-flow timelines |
tools/wireshark/packclient.lua |
Display protocol metadata in Wireshark/TShark |
The Python CLIs require Python 3.11–3.13 and the standard library. LZ4 support and detection-engine tests have separate pinned optional dependencies. The quickstart creates a deterministic synthetic input without any malware.
python -B -m unittest discover -s tests -vThe optional synthetic IPC kit exercises the reconstructed 1RCP contract using benign deterministic inputs and outputs, without malware or desktop capture.
The Sigma, Suricata and YARA rules are included as experimental detection candidates with regression coverage. Production accuracy has not been measured.
The Core and historical successful Launcher-to-Core transport are now recovered. The available evidence still does not identify the external 1RCP peer, contain a delivered plugin binary, prove a bridge between 1RCP and Core PV10, recover the server implementation, establish a complete real 1RCP exchange, or prove the causal diagnosis of the worker failure. The two September reruns reached the server but received no application response.
Additional reproducibility gaps are documented in Evidence and Limitations.
PackClient was previously documented by Proofpoint and Deception.Pro. This work adds implementation details from the recovered carrier, Launcher and Core build while separating prior reporting from independent reconstruction. See Prior Work for more details.
Use CITATION.cff to cite the report.
Research cut-off: 9 September 2026.
Updated publication date: 9 September 2026.

