PUBLOAD

MITRE ATT&CK: S1228 View on attack.mitre.org

Aliases: ClaimLoader, PUBLOAD

First seen
2018-06-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-28 14:42:28
Profile updated
2026-07-07 12:54:19

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:vn country_code:my

Context

PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components. PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to PUBLOAD (S1228). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-04-05_0d9bf108a58ab85ea145230ccfb192b2_cobalt-strike_icedid_satacom_vidar 2026-07-28 1

Detection coverage

  • 1 YARA rules
  • 583 Sigma rules

Malware & tools used

  • Security Software Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Compression (attack-pattern)
  • Process Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • Wi-Fi Discovery (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • DLL (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Environmental Keying (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Native API (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Traffic Signaling (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Pubload_Auto (yara-rule)

Reports & references

  • Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
  • ESET — Separating Bee Panda Ceranakeeper Making Beeline Thailand (report)
  • csirt-cti.net — Stately Taurus Targets Myanmar (report)
  • ibm.com — Hive0154 Targeting Us Philippines Pakistan Taiwan (report)
  • Cisco Talos — Mustang Panda Targets Europe (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pubload (report)
  • twitter.com — 1556940169483264000 (report)
  • Palo Alto Unit 42 — Chinese Apts Target Asean Entities (report)
  • ibm.com — Hive0154 Drops Updated Toneshell Backdoor (report)
  • lac.co.jp — 20221117 003189 (report)
  • MITRE ATT&CK — S1228 (report)

External references