PUBLOAD is a Windows malware family associated with the China-aligned espionage ecosystem commonly tracked as Mustang Panda, Earth Preta, Hive0154, ITG27, and Stately Taurus. It is most consistently described as a downloader or stager used to establish initial control on a compromised host, communicate with command-and-control infrastructure, and retrieve or launch follow-on payloads including shellcode and additional malware such as PlugX, TONESHELL, and FDMTP. Reporting also describes closely related tooling under the name PUBSHELL and notes architectural similarities with TONESHELL and other malware in the same operational cluster.
PUBLOAD is frequently deployed through spearphishing campaigns using decoy documents and weaponized archives, including lures themed around government, diplomatic, and geopolitical subjects in the Asia-Pacific region. In multiple campaigns, operators embedded cloud-storage links such as Google Drive links in decoy documents to deliver password-protected archives. It has also been observed in worm-enabled intrusion chains where a removable-drive propagation component delivered PUBLOAD into victim environments. Execution commonly relies on DLL sideloading through legitimate signed executables, and operators have also used valid digital signatures and certificates as part of broader defense-evasion tradecraft.
Once active, PUBLOAD functions as a main control utility or staging implant. Observed variants perform host and network reconnaissance, including discovery of installed antivirus products, system configuration, users, processes, network settings, and routing information. It can execute commands, download shellcode or secondary payloads, launch additional tools, and support collection workflows by invoking legitimate utilities for archiving and transfer. In espionage operations attributed to Mustang Panda and related clusters, PUBLOAD has been used to run collection tooling, compress documents with RAR, and exfiltrate data using command-line transfer utilities or FTP-based workflows. Some variants maintain persistence through autorun-style mechanisms and scheduled tasks.
Operational reporting links PUBLOAD to campaigns targeting government, diplomatic, and critical-sector organizations, especially in Asia-Pacific, including energy-sector and Southeast Asian government-focused intrusions. Infrastructure and tradecraft overlaps also connect PUBLOAD to Bookworm-related activity and to broader Mustang Panda malware evolution from long-running PlugX operations toward newer families such as TONESHELL, LOTUSLITE, SnakeDisk, and FDMTP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Associated malware families such as Toneshell, Pubload and Claimloader undergo frequent updates that enhance ITG27’s adaptability within their target environments.
Associated malware families such as Toneshell, Pubload and Claimloader undergo frequent updates that enhance ITG27’s adaptability within their target environments.
UNK_SteadySplit is a user of the custom TONESHELL and PUBLOAD malware families, alongside multiple other first-stage malware families delivered in phishing campaigns.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
HIUPAN spreads through removable drives to deliver PUBLOAD.
Throughout mid-2025, X-Force observed several weaponized archives uploaded to VirusTotal from Singapore and Thailand... The archive "CallNotes.zip" discovered in September was downloaded from Box Cloud Storage through a link in a PDF lure impersonating the Myanmar Ministry of Foreign Affairs.
PUBLOAD has its own installation routine, which includes copying all components to its install path and creating autorun registry entry and a scheduled task.
facilitate two active reverse shells in parallel... Yokai, a backdoor that sets up a reverse shell to execute arbitrary commands.
Similar to previous variants, a reverse shell is set up using anonymous pipes connected to stdin and stdout handles of a new cmd.exe process... Toneshell operators can write string data to the pipe using the correct shell_id and execute arbitrary commands on the machine.
Victims will receive and interact with a decoy document containing a Google Drive link and a corresponding password instead of an archive download link embedded in the email.
The document lures users into downloading a malicious password-protected archive with the embedded link. The files can then be extracted inside via the password provided in the document.
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The HTTP request includes www.asia.microsoft.com within the host field as an attempt to masquerade as a legitimate request associated with the Windows operating system. Also, the URL pattern seen in these HTTP requests appears to be an attempt to mimic legitimate URLs accessed by Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The TONEINS malware, libcef.dll, will decrypt this file with a single byte in XOR operations, find the PE header, and drop the payload
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
Commands like ipconfig and netsh are used to discover network configuration.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
The decrypted payload contains another payload that is XOR-encrypted... After this is decrypted, there is yet another final backdoor payload
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in the malware/tools list without further discussion in the content.
Named as part of ITG27's malware arsenal and described as an associated malware family undergoing frequent updates, but no technical behavior is detailed in this reference.
A downloader previously used to distribute FDMTP as a secondary payload.
Loader/downloader families linked to the same Mustang Panda operational ecosystem and architecturally similar to TONESHELL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.