2026-08-27 (Back to Inventory) Carry-On Compromise: TA4922 Packs PackClient Author(s): Kyle Cucci , Proofpoint Threat Research Team , Rob Kinner , Tony Robinson Organization: Proofpoint win.donut_injector Open article directly Open article on Archive.org Related Articles 2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress 2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan TA488 Targets Zimbra Mailservers with Half-Click Exploits ZimReaper 2026-07-07 ⋅ Proofpoint ⋅ Greg Lesnewich , Mark Kelly , Proofpoint Threat Research Team One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube
The threat actor TA4922 is distributing a new malware payload dubbed "PackClient" via a campaign named "Carry-On Compromise," which leverages a malicious win.donut_injector tool. The article does not provide a CVSS score, specific affected software versions, a fixed version, or a recommended workaround.