CLAIMLOADER
MITRE ATT&CK: S1236 View on attack.mitre.org
Aliases: CLAIMLOADER
- First seen
- 2021-01-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:19:16
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn country_code:vn
Context
CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be leveraged by Mustang Panda and was first observed utilized in 2021.
Detection coverage
- 218 Sigma rules
Malware & tools used
- Component Object Model (attack-pattern)
- Native API (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- DLL (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Malicious File (attack-pattern)
- Scheduled Task (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Dynamic API Resolution (attack-pattern)
Used by threat actors
- Mustang Panda (threat-actor)
Reports & references
- ibm.com — Hive0154 Mustang Panda Shifts Focus Tibetan Community Deploy Pubload Backdoor (report)
- ibm.com — Hive0154 Targeting Us Philippines Pakistan Taiwan (report)
- MITRE ATT&CK — S1236 (report)