PUBLOAD is a downloader/stager malware family associated with the China-aligned threat actor Mustang Panda, also tracked as Stately Taurus and Hive0154. It has been publicly documented since at least early 2022 and has been used in cyber-espionage campaigns targeting government entities in the Asia-Pacific region, including Southeast Asian governments and members of the Tibetan community. Delivery methods described in the source material include spear-phishing archives, weaponized ZIP/RAR files, DLL sideloading chains, and propagation via infected removable drives using HIUPAN/USBFect. In observed campaigns, legitimate executables such as Talking_Points_for_China.exe or other signed binaries loaded malicious DLLs including KeyScramblerIE.dll, BrMod104.dll, and Claimloader to execute PUBLOAD in memory.
Functionally, PUBLOAD acts as a first-stage loader/backdoor that communicates with command-and-control infrastructure to obtain additional shellcode-based payloads and further instructions. Reported variants support command and control over either HTTP or raw TCP traffic that imitates TLS, and can download shellcode payloads via HTTP POST requests. One described variant supports decoy C2 servers. PUBLOAD has been used to deliver follow-on malware including PlugX, and reporting also states it can act as a conduit for additional Mustang Panda tooling such as FDMTP and PTSOCKET. In one Southeast Asian government intrusion, PUBLOAD collected host information including volume details, computer names, usernames, and system tick counts, then transmitted the data over TCP using obfuscated TLS-like headers. Other reporting states PUBLOAD can conduct reconnaissance, harvest document files such as .doc, .docx, .xls, .xlsx, .pdf, .ppt, and .pptx, and use curl to exfiltrate RAR archives of targeted documents to an attacker-controlled FTP site. Connectivity discovery behavior cited for PUBLOAD includes use of commands such as tracert -h 5 -4 google.com and curl http://myip.ipip.net.
Persistence and evasion behaviors directly mentioned include creation of a scheduled task using schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 ..., establishment of autorun persistence by Claimloader in one infection chain, and use of valid legitimate digital signatures and certificates to evade detection. PUBLOAD traffic has been disguised as Microsoft Windows Update activity by using HTTP POST requests with host fields such as www.asia.microsoft.com and fake Windows Update-style URL paths including /v11/2/windowsupdate/redir/v6-winsp1-wuredir. Infrastructure and indicators explicitly cited in the content include C2 IPs 188.208.141.196 and 123.253.32.15, and domains/paths overlapping with Bookworm-related campaigns such as www.fjke5oe[.]com, update.fjke5oe[.]com, and the anomalous Windows Update-like redirection path. Overall, the content consistently characterizes PUBLOAD as a Mustang Panda-linked downloader/stager used in espionage-focused intrusion chains, especially against government targets in Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Throughout mid-2025, X-Force observed several Toneshell and Pubload malware variants in weaponized archives... Hive0154 was observed using a new loader to reflectively inject either Pubload or Toneshell7.
UNK_SteadySplit is a user of the custom TONESHELL and PUBLOAD malware families, alongside multiple other first-stage malware families delivered in phishing campaigns.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Mustang Panda notably utilized the USBFect worm to propagate PUBLOAD via infected USB drives, enabling lateral movement and data exfiltration.
Mustang Panda, also called Camaro Dragon, Earth Preta, and Stately Taurus, is believed to have targeted entities in Myanmar, the Philippines, Japan and Singapore, targeting them with phishing emails designed to deliver two malware packages.
Throughout mid-2025, X-Force observed several weaponized archives uploaded to VirusTotal from Singapore and Thailand... The archive "CallNotes.zip" discovered in September was downloaded from Box Cloud Storage through a link in a PDF lure impersonating the Myanmar Ministry of Foreign Affairs.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
facilitate two active reverse shells in parallel... Yokai, a backdoor that sets up a reverse shell to execute arbitrary commands.
Similar to previous variants, a reverse shell is set up using anonymous pipes connected to stdin and stdout handles of a new cmd.exe process... Toneshell operators can write string data to the pipe using the correct shell_id and execute arbitrary commands on the machine.
"BOOKWORM ... execution on the heap is initiated through callback function of legitimate API functions such as EnumChildWindows or EnumSystemLanguageGroupsA"; "CLAIMLOADER ... run its shellcode through the callback function"; "PUBLOAD stager leveraged Windows API functions with callback ... to bypass anti-virus monitoring"
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The HTTP request includes www.asia.microsoft.com within the host field as an attempt to masquerade as a legitimate request associated with the Windows operating system. Also, the URL pattern seen in these HTTP requests appears to be an attempt to mimic legitimate URLs accessed by Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The malware copies its components to a working directory... These components include: A legitimate parent process ClaimLoader itself
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
"Bazar can query the Registry for installed applications." / "BRONZE BUTLER has used tools to enumerate software installed on an infected host." / "LightSpy ... enumerate the Applications folder to collect the bundle name, bundle identifier, and version information..." / "Volt Typhoon has queried the Registry on compromised systems for information on installed software."
Multiple malware families (e.g., Avaddon, Bazar, Clop, Ryuk, REvil, LockBit, Zeus Panda) check OS language/keyboard layout/locale and terminate or alter execution if the system matches excluded languages (commonly Russian/CIS) or does not match desired target languages (e.g., Spanish/Portuguese, Arabic, Persian).
PUBLOAD is equipped with features to conduct reconnaissance of the infected network and harvest files of interest (.doc, .docx, .xls, .xlsx, .pdf, .ppt, and .pptx) ... PlugX then takes care of deploying another bespoke file collector called FILESAC that can collect the victim's files.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
This particular PubLoad payload communicates with its C2 server by directly connecting to the IP address 123.253.32[.]15. The payload then issues an HTTP request... The HTTP request includes www.asia.microsoft.com within the host field as an attempt to masquerade as a legitimate request associated with the Windows operating system.
PUBLOAD collected and exfiltrated critical system information... over TCP with obfuscated TLS-like headers
The captured information is compressed into an RAR archive and exfiltrated to an attacker-controlled FTP site via cURL. Alternatively, Mustang Panda has also been observed deploying a custom program named PTSOCKET that can transfer files in multi-thread mode.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only in infrastructure comparison to support attribution, via a previously identified C2 server associated with Mustang Panda.
Referenced as part of Mustang Panda's evolving malware/tooling ecosystem.
A named malware/tool repeatedly deployed by the Mustang Panda cluster in recent attacks.
Malware used in the campaign and propagated by USBFect via infected USB drives to support lateral movement and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.