Evidence and claim boundaries
Research cut-off: 5 September 2026 (UTC).
Evidence standard
| Class | Meaning |
|---|---|
| Direct | Identity-pinned static bytes, deterministic engineering result, native artifact observation or unambiguous captured UI |
| Strongly supported | Converging direct evidence with an unresolved external/runtime edge |
| Inference | Consistent with recovered architecture, dependent on missing bytes/state |
| Unresolved | Available evidence does not establish the proposition |
Static claims are based on the identity-pinned reconstruction. Runtime claims are supported by the process, task, memory, network, and debugger observations documented below and in runtime validation. Synthetic tests validate only the mechanics they exercise.
Claim ledger
| Claim | Status and basis | Boundary/reference |
|---|---|---|
| Tax Notice host/carrier and embedded A/B lineage | Direct: exact hashes, verified IMG contents, transformed package and PE structure | One recovered build. See architecture. |
| Colocated NVDA helper sideload | Direct static import/placement plus runtime Load Image events | Legitimate host signature does not assess carrier |
| Package specifically generated by Donut | Unresolved | Call-over-data and configuration string are insufficient |
| Lower framing and PLH1/PLC1/PLA1 layouts | Direct static contract; synthetic verification | No successful captured session. See protocol reference. |
| PLA1 HMAC-SHA-256 and exact 42-byte transcript | Direct static dataflow and deterministic tests | Server challenge generation absent |
Type 0x16 authenticates before AES-256-CBC decrypt |
Direct static API/dataflow and tests | Envelope-key initialization and runtime use unresolved |
| PSK supplies envelope keys | Not established | Keys are separate 32-byte inputs; no KDF was recovered |
| Other syntactically accepted lower types have semantics | No supported semantics in B | Only 0x15 is constructed/dispatched; 0x16 is the inbound wrapper |
| PLK1 size/sequence/hash and mandatory cache round trip | Direct static call/branch contract | Successful transfer/cache result not observed |
| Cache uses current-user DPAPI | Strongly supported: resolved capabilities, inverse dataflow and metadata marker | Absolute cache base unresolved |
| Secondary Core is an active failover slot | Not supported for this build | Both pull callers use slot 0; no promotion/cross-slot edge |
| Pulled vector is Core | High-confidence role inference | No independent Core bytes/hash/export implementation |
| Worker invocation, header and BGRX format | Direct static reconstruction | Worker/client half only. See screenshot IPC. |
| Endpoint is a named pipe | Strongly supported intended use | CreateFileW also accepts other path types |
Recovered code creates the external 1RCP peer or consumes type-2 pixels |
Scoped negative | No recognizable local implementation; external component missing |
| B sends framebuffer directly to lower transport/JPEG/PV10 | Scoped negative | B-local dataflow ends at endpoint WriteFile |
| Bitmap deletion call precedes later bits-pointer copy | Direct call order; potential lifetime hazard | Successful deletion and causal use after free not established |
| Final worker attempt failed with no READY header | Direct captured AV and 0/20-byte timeout | EDI 0x13C, EAX 1; debugger-modified attempt, no controlled repair |
Completed real 1 -> 3 -> 2 -> 5 exchange |
Not established | No real READY/type-2 capture |
Benign peer/simulator matches the reconstructed 1RCP contract |
Direct engineering result from the published synthetic kit | Validates protocol mechanics, not real-worker behavior. See synthetic validation. |
| Active-session token and spawn contracts | Direct static dataflow | Current-process primary token; WTS/process token is environment-only. See active-session handoff. |
Session drift samples valid inequality and replaces with -acsi |
Direct static state machine | Successful runtime handoff not observed |
| Mutex export releases held session guard | Direct static effect | No recovered external caller |
| Launcher self-dump requests full/private memory | Not supported | Type 0x1001, DataSegs plus ThreadInfo |
| PID 5812 task persistence and bare surrogate | Direct task/process evidence | HighestAvailable is not SYSTEM. See runtime validation. |
| A/B resident and active in PID 5812 | Direct/strongly supported: exact maps, A-entry thread, immutable sections, VMMap and B-specific state | Upstream placement/injection subtype unresolved |
| PID 5812 used port 443 and timed out | Direct concrete environment/log state | WSA 10060, not a successful C2 session |
| PID 5812 Procmon capture covers detonation | Not established | Capture begins 44m45s after PID 5812 start and spans 9.48 seconds |
| PID 3696 sideload, high-integrity relaunch, and persistence | Direct Procmon/Sysmon/Autoruns/task evidence with visual corroboration | Observed across an interrupted session with multiple launch attempts. See runtime validation. |
| Package and private mapped B in PID 3696 | Direct recorded package/PE comparison and private mapping | See the detailed comparison in runtime validation. |
| Eight package differences are exactly three simple port substitutions | Unresolved | Eight reported bytes vs six explained; exact before/after transcript absent |
| PID 3696 shows repeated SYN_SENT endpoints | Direct Process Explorer observations | Socket-level association at those moments only |
| 373 ICMP messages quote failed SYNs to port 443 | Direct offline packet analysis | Packet capture has no PID metadata; per-packet process attribution is correlation |
| Core PE identified in either dump | Not identified in the bounded censuses | Headerless, unrecognized, uncaptured, or earlier state remains possible |
| Successful C2, authentication, PLK1 or encrypted traffic | Not established | Both runtime sessions preserve failed connection behavior |
| Tool mechanics pass deterministic synthetic cases | Reproducible under documented dependencies | See tooling. |
| Detection accuracy/real-capture compatibility measured | Not established | No representative corpus or established-session capture |
| Absolute priority or discovery of PackClient | Not claimed | PackClient and its campaign markers predate this research. See prior work. |
Runtime evidence sources
The observations above were supported by the following source classes. Exact timings, addresses, and correlations are documented in runtime validation and screenshot IPC.
| Evidence set | Sources used | Main observations supported |
|---|---|---|
| PID 5812 session | Process tree, task XML, process dump, VMMap, late Procmon capture, focused screenshots | Bare PID 5812 surrogate, NvSvc persistence, transformed package and mapped A/B, A-entry thread, launcher-specific state, configured endpoint and timeout |
| PID 3696 session | Procmon, Sysmon, Autoruns, task XML, process dump, packet capture, Process Explorer, focused screenshots | DLL sideload, high-integrity relaunch, Run/RunOnce and task persistence, PID 3696 private B mapping, SYN_SENT state and failed outbound attempts |
| Screenshot-worker experiments | Debugger captures and the benign local peer/simulator | Worker control flow, framebuffer contract, observed failure, and synthetic 1RCP protocol validation |