Pubshell is a lightweight backdoor/reverse-shell payload associated with the China-aligned threat actor Hive0154, which overlaps with reporting under names including Mustang Panda, Stately Taurus, Camaro Dragon, Twill Typhoon, Polaris, and Earth Preta. It is commonly delivered as a later-stage payload by Pubload, often after Claimloader is used in DLL sideloading chains initiated from weaponized ZIP or RAR archives distributed via spear-phishing. Reported lures were themed around geopolitical topics, including Tibet-related subjects, and targeted entities such as the Tibetan community as well as government, military, and diplomatic organizations in countries including the United States, Pakistan, Taiwan, the Philippines, and India.
Its core functionality is to provide immediate access to an infected machine by creating a reverse shell through anonymous pipes. Reporting states it is less sophisticated than Toneshell and supports cmd.exe as its shell. IBM X-Force described it as a lightweight backdoor facilitating immediate access via a reverse shell. The shellcode payload downloaded by Pubload and identified as Pubshell was reported to share similarities with Toneshell variants and to have the same basic functionality of establishing a reverse shell.
Pubshell is part of a broader Hive0154 malware ecosystem that includes Claimloader, Pubload, Toneshell, HIUPAN, SnakeDisk, and Yokai. The content notes code and tradecraft overlaps among Pubload, Pubshell, and Toneshell, indicating related development. High-confidence behavioral context from the reporting is that Pubload downloads encrypted shellcode payloads including Pubshell, and that campaigns using these components relied on DLL sideloading, decoy documents, and phishing-delivered archives for infection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Interestingly, Yokai shows overlaps with other backdoor families attributed to Hive0154, such as Pubload/Pubshell and Toneshell.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as used in a Mustang Panda campaign targeting the Tibetan community.
A related backdoor family mentioned only for structural comparison with Yokai and Toneshell.
A reverse-shell payload retrieved by the PUBLOAD loader to provide interactive access/remote command execution on compromised hosts.
Lightweight backdoor that provides immediate access to compromised machines via a reverse shell. Used as a next-stage payload after PUBLOAD.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.