ClaimLoader is a Windows malware loader associated with the China-aligned espionage cluster tracked as ITG27, Hive0154, and Mustang Panda/Stately Taurus overlaps. It is used as an intermediate stage in targeted intrusion chains to decrypt and execute in-memory payloads, most notably PUBLOAD and TONESHELL-family backdoors, and has appeared in campaigns against government, diplomatic, political, and energy-sector targets, including Tibetan community targeting and operations aligned with Chinese strategic interests.
Operationally, ClaimLoader is commonly delivered through spearphishing lures packaged in archives that contain a legitimate executable and a malicious DLL for side-loading. The malware has repeatedly abused signed or otherwise legitimate binaries to launch the DLL, often presenting decoy documents or themed content to induce user execution. Variants have also been observed in USB-propagated infection chains, where related worm activity spreads components laterally across endpoints and invokes ClaimLoader to recover and run shellcode in memory.
ClaimLoader’s core role is loader functionality rather than long-term command-and-control. Documented variants decrypt embedded strings, dynamically resolve imports using obfuscated or XOR-encrypted API names, and use native loader routines such as LdrLoadDll and LdrGetProcedureAddress to reduce static visibility. It creates a mutex in some variants, copies or renames itself into staging directories, modifies file attributes to remain hidden from users, and establishes persistence through Windows autorun mechanisms including Run-key entries and scheduled tasks. Some variants create scheduled tasks programmatically through COM interfaces such as ITaskService, while others invoke schtasks directly at frequent intervals.
For payload execution, ClaimLoader has been observed decrypting shellcode and launching it through callback-based execution techniques, including APIs such as EnumFontsW and EnumSystemLocalesA. This tradecraft is consistent with its use as a shellcode loader designed to evade straightforward detection while handing off execution to follow-on espionage implants. The downstream payloads linked to ClaimLoader include PUBLOAD, PUBSHELL, and TONESHELL, which provide backdoor access, reverse shell capability, file operations, and data theft support for hands-on-keyboard espionage activity.
ClaimLoader is best characterized as a specialized espionage loader within the broader Mustang Panda tooling ecosystem. Its recurring use of DLL side-loading, hidden artifacts, decoy-assisted execution, scheduled-task persistence, and in-memory shellcode execution makes it a flexible staging component for sustained cyber-espionage operations against high-value Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The DLL functions as a malware loader that X-Force tracks as a new variant of Claimloader, a malware family consistently associated with ITG27 intrusion activity.
The DLL functions as a malware loader that X-Force tracks as a new variant of Claimloader, a malware family consistently associated with ITG27 intrusion activity.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The Mustang Panda activity, recorded between June 1 and August 15, 2025, entailed the use of a USB-based malware known as HIUPAN to deliver the PUBLOAD backdoor by means of a rogue DLL codenamed Claimloader.
an execution chain of payloads delivered via Phishing from another Threat Actor China-Nexus... In this research, I will explore a campaign by Threat Actor Mustang Panda
In May 2026, X-Force uncovered an email with the subject ‘China BG’ delivered to recipients within the Indian government. The email includes a PDF attachment titled, “Hydropower Cooperation Project Study.pdf” imitating Nepal’s Ministry of Foreign Affairs (MoFA).
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st
"BOOKWORM ... execution on the heap is initiated through callback function of legitimate API functions such as EnumChildWindows or EnumSystemLanguageGroupsA"; "CLAIMLOADER ... run its shellcode through the callback function"; "PUBLOAD stager leveraged Windows API functions with callback ... to bypass anti-virus monitoring"
The malware copies the sideloading pair to a new installation directory ... recovers embedded shellcode and executes Toneshell payload using a Windows enumeration callback.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Examples include: "Sandworm Team leveraged Microsoft Office attachments which contained malicious macros..."; "Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs"; "Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files."
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The string decryption routine is quite simple, essentially an XOR operation on a single-byte key... Another custom string decryption algorithm... The XOR key is composed of a 4-byte array
all strings encrypted by this algorithm refer to APIs that will be dynamically loaded... parse the ntdll.dll module to load the LdrLoadDll API... followed by the decrypted API being loaded via the LdrGetProcedureAddress API.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The loaders subsequently execute embedded shellcode using the EnumSystemLocalesA API as a callback mechanism.
The archive contains a legitimate executable ... which side-loads the malicious DLL loader, “SolidPDFCreator.dll”.
This is the malware’s main function... Basically, this function performs the following actions: Decrypts Strings; Checks the Passed Argument; Creates a Mutex; Creates Persistence on the Infected System
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used by ITG27 via DLL side-loading. It copies the sideloading pair into C:\ProgramData\IDM\logs\, establishes persistence through a Run key, executes shellcode via EnumSystemLocalesA, and deploys Toneshell v10 in memory.
A loader-stage implant associated with ITG27. It side-loads via a malicious DLL, copies itself and a legitimate executable into ProgramData, establishes persistence via a Run key, recovers embedded shellcode, and executes the Toneshell payload in memory using EnumSystemLocalesA as a callback.
Mentioned only as a comparative loader family with similar callback-API execution style.
A loader used to decrypt and execute shellcode in memory as part of the intrusion chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.