MemLoader HidenDesk is a reflective PE loader used by the Mysterious Elephant APT. It is loaded by the BabShell C++ reverse shell and is used to load and execute malicious payloads directly in memory, including a Remcos RAT sample (MD5: 037b2f6233ccc82f0c75bf56c47742bb). The malware uses encryption and compression to evade detection, and one reported implementation used an RC4-like algorithm with the key D12Q4GXl1SmaZv3hKEzdAhvdBkpWpwcmSpcD to decrypt embedded data and execute shellcode. Reported anti-analysis behavior includes terminating itself if fewer than 40 processes are running. For persistence, it creates an autostart shortcut to survive reboot. It also creates and switches to a hidden desktop named "MalwareTech_Hidden." MemLoader HidenDesk has been observed in campaigns attributed to Mysterious Elephant targeting government and foreign affairs entities in the Asia-Pacific region, especially South Asia, with notable focus on Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. In the broader intrusion chain, initial access was achieved via spear-phishing, exploit kits, and malicious documents, with PowerShell-based staging and persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MemLoader HidenDesk is a loader that executes the Remcos RAT payload in memory, facilitating fileless malware execution.
In-memory reflective loader with sandbox evasion (self-terminates if <40 processes), persistence via Startup shortcut, hidden-desktop execution ('MalwareTech_Hidden'), and RC4-like decryption of embedded shellcode that loads a PE payload (noted as Remcos in this campaign).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.