HUI Loader is a custom malware loader used in China-nexus intrusion activity. Reporting in the provided content links it to Chinese state-directed cyberespionage operations, including Sophos-tracked Operation Crimson Palace and SentinelLABS reporting on activity targeting the Southeast Asian gambling sector, and notes that several China-aligned groups have used it. It is commonly deployed through DLL sideloading / DLL search order hijacking using legitimate executables. Observed malicious DLL variants identified as HUI Loader include libcef.dll, msedge_elf.dll, and LockDown.dll, sideloaded by legitimate components such as Microsoft Edge identity_helper.exe, Adobe Creative Cloud-related binaries, McAfee VirusScan mfeann.exe, and other trusted executables. In multiple cases the sideloading package also included an encrypted data file such as agent.data or log.ini containing the next-stage payload.
Its primary observed role is staging and injecting follow-on payloads, especially Cobalt Strike Beacon. Sophos reported HUI Loader being used by Cluster Charlie in Operation Crimson Palace to inject a Cobalt Strike Beacon into mstsc.exe, and another report described identity_helper.exe sideloading msedge_elf.dll, which unpacked log.ini into a reflective Cobalt Strike loader and Beacon injected into mstsc.exe. SentinelLABS also described HUI Loader variants delivering encrypted Cobalt Strike beacons from password-protected ZIP archives downloaded from Alibaba OSS buckets, including chains using identity_helper.exe with msedge_elf.dll and mfeann.exe with LockDown.dll. Mentioned C2-related indicators for these beacon deployments include www.100helpchat[.]com, live100heip[.]com, and duckducklive[.]top.
The content states that HUI Loader can disable Windows Event Tracing for Windows (ETW) and the Antimalware Scan Interface (AMSI), indicating defense-evasion capability in addition to payload staging. It is described as often being sideloaded by legitimate executables and used to stage encrypted payloads. The content also notes historical appearance of HUI Loader in incidents associated with BRONZE RIVERSIDE / APT10, APT41-related reporting, and ransomware operations involving LockFile, AtomSilo, NightSky, LockBit 2.0, and Pandora, though exact attribution remains uncertain because Chinese threat groups frequently share tooling and infrastructure. Additional artifact context in the content includes a libcef.dll sample referencing C:\Users\hellokety.ini.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malicious DLLs libcef.dll, msedge_elf.dll, and LockDown.dll distributed by agentupdate_plugins.exe and AdventureQuest.exe are HUI Loader variants.
The malicious DLLs libcef.dll, msedge_elf.dll, and LockDown.dll distributed by agentupdate_plugins.exe and AdventureQuest.exe are HUI Loader variants.
The malicious DLLs libcef.dll, msedge_elf.dll, and LockDown.dll distributed by agentupdate_plugins.exe and AdventureQuest.exe are HUI Loader variants.
Regarding the connection between the A41APT campaign and attack groups, they discussed the possibility of multiple attack groups involved, based on the fact that security researchers overseas identified HUI Loader in LockFile ransomware and BRONZE RIVERSIDE (a.k.a. APT10) incidents.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The zip archives downloaded by agentupdate_plugins.exe and AdventureQuest.exe contain sideloading capabilities. Each of the archives we were able to retrieve consists of a legitimate executable vulnerable to DLL search order hijacking, a malicious DLL that gets sideloaded by the executable when started, and an encrypted data file named agent.data.
using a custom malware loader called HUI loader to inject a Cobalt Strike beacon into the Remote Desktop utility mstsc.exe... the attackers used the Havoc tool to inject code into other processes
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
The threat actors drop Adobe Creative Cloud, Microsoft Edge, and McAfee VirusScan executables vulnerable to DLL hijacking to deploy Cobalt Strike beacons.
The zip archives downloaded by agentupdate_plugins.exe and AdventureQuest.exe contain sideloading capabilities. Each of the archives we were able to retrieve consists of a legitimate executable vulnerable to DLL search order hijacking, a malicious DLL that gets sideloaded by the executable when started, and an encrypted data file named agent.data.
agentupdate_plugins.exe and AdventureQuest.exe deploy .NET executables based on the SharpUnhooker tool, which download second-stage data from Alibaba buckets hosted at agenfile.oss-ap-southeast-1.aliyuncs[.]com and codewavehub.oss-ap-southeast-1.aliyuncs[.]com. The second-stage data is stored in password-protected zip archives.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom loader used to de-obfuscate and stage encrypted payloads; in this case it unpacked and injected a Cobalt Strike reflective loader and beacon.
A custom malware loader used to inject a Cobalt Strike beacon into mstsc.exe for stealthy execution.
A custom malware loader used to inject a Cobalt Strike Beacon into mstsc.exe.
A custom malware loader used to inject a Cobalt Strike beacon into mstsc.exe, helping the threat actor deploy payloads while blending into legitimate processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.