hcdLoader

MITRE ATT&CK: S0071 View on attack.mitre.org

Aliases: hcdLoader

First seen
2014-06-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:46:37

Targeted industries: healthcare-and-pharmaceutical government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:cn

Context

hcdLoader is a remote access tool (RAT) that has been used by APT18.

Detection coverage

  • 65 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Windows Service (attack-pattern)

Used by threat actors

Reports & references

  • secureworks.com — Where You At Indicators Of Lateral Movement Using At Exe On Windows 7 Systems (report)
  • MITRE ATT&CK — S0071 (report)
  • MITRE ATT&CK — S0071 (report)

External references