PUBLOAD
MITRE ATT&CK: S1228 View on attack.mitre.org
Aliases: ClaimLoader, PUBLOAD
- First seen
- 2018-06-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-28 14:42:28
- Profile updated
- 2026-07-07 12:54:19
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn country_code:vn country_code:my
Context
PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components. PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to PUBLOAD (S1228). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2026-04-05_0d9bf108a58ab85ea145230ccfb192b2_cobalt-strike_icedid_satacom_vidar | 2026-07-28 | 1 |
Detection coverage
- 1 YARA rules
- 583 Sigma rules
Malware & tools used
- Security Software Discovery (attack-pattern)
- Code Signing (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Language Discovery (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Scheduled Task (attack-pattern)
- Debugger Evasion (attack-pattern)
- Compression (attack-pattern)
- Process Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Wi-Fi Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- DLL (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Environmental Keying (attack-pattern)
- Windows Command Shell (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Native API (attack-pattern)
- Archive via Utility (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Traffic Signaling (attack-pattern)
Used by threat actors
- Mustang Panda (threat-actor)
Detection rules
- MALPEDIA_Win_Pubload_Auto (yara-rule)
Reports & references
- Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
- ESET — Separating Bee Panda Ceranakeeper Making Beeline Thailand (report)
- csirt-cti.net — Stately Taurus Targets Myanmar (report)
- ibm.com — Hive0154 Targeting Us Philippines Pakistan Taiwan (report)
- Cisco Talos — Mustang Panda Targets Europe (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pubload (report)
- twitter.com — 1556940169483264000 (report)
- Palo Alto Unit 42 — Chinese Apts Target Asean Entities (report)
- ibm.com — Hive0154 Drops Updated Toneshell Backdoor (report)
- lac.co.jp — 20221117 003189 (report)
- MITRE ATT&CK — S1228 (report)