Yokai is a Windows backdoor associated with China-aligned espionage activity linked to the Mustang Panda / Hive0154 cluster and campaigns focused on Thailand, including intrusions against Thai government and law-enforcement targets. It has been observed as a previously undocumented family used to provide operators with remote command execution through a reverse shell implemented with anonymous pipes and a spawned command interpreter. Variants collect basic host identity information such as username and hostname during initial check-in, communicate with command-and-control infrastructure over HTTP or raw TCP depending on the sample, and support interactive shell command execution and related post-compromise tasking. Some reporting also notes data exfiltration behavior within its command loop.
Yokai has been delivered through multiple infection chains. One prominent method uses DLL side-loading via legitimate Windows applications, including abuse of a signed data recovery executable to load a malicious DLL. Other observed chains use shortcut-file lures embedded in archive files with decoy government-themed documents, including FBI-themed material aimed at Thai recipients. Yokai has also been deployed by the SnakeDisk and TONEDISK/WispRider USB-propagating worm families, indicating use in removable-media operations and potential access to segmented or tightly controlled environments. In USB-borne campaigns, Yokai is dropped after the propagation component infects removable drives and executes on selected hosts.
Persistence mechanisms vary by variant. Reported samples establish persistence either through scheduled tasks or through user Run-key autorun entries, and they use mutexes or events to avoid duplicate execution. Some variants use XOR-based encryption for command-and-control traffic and receive session-specific values from the server to continue communications. The malware’s tradecraft, delivery themes, and code overlaps place it within the broader Mustang Panda malware ecosystem alongside families such as TONESHELL, PUBLOAD, and related USB worm tooling. The targeting and geofencing observed in several campaigns indicate a strong operational emphasis on Thai entities and broader Southeast Asian espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The worm only executes on devices with Thailand-based IP addresses and drops the Yokai backdoor... Yokai is used to create a reverse shell through anonymous pipes, allowing operators to execute arbitrary commands on the infected machine.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
If IdrInit.exe is executed as a non-admin user, Yokai creates a scheduled task, even if it already exists, named “MicrosoftTSUpdate” which executes IdrInit.exe every five minutes.
Upon execution, the malware first checks for the "-project-mod" argument and then establishes persistence via a scheduled task if the user is not a member of the Administrator's group: cmd.exe /c schtasks /create /f /sc MINUTE /MO 5 /tn "MicrosoftEdgeAcModuleUpdateTask" /tr "<path> -project-mod"
facilitate two active reverse shells in parallel... Yokai, a backdoor that sets up a reverse shell to execute arbitrary commands.
Similar to previous variants, a reverse shell is set up using anonymous pipes connected to stdin and stdout handles of a new cmd.exe process... Toneshell operators can write string data to the pipe using the correct shell_id and execute arbitrary commands on the machine.
If IdrInit.exe is executed as a non-admin user, Yokai creates a scheduled task, even if it already exists, named “MicrosoftTSUpdate” which executes IdrInit.exe every five minutes.
Upon execution, the malware first checks for the "-project-mod" argument and then establishes persistence via a scheduled task if the user is not a member of the Administrator's group: cmd.exe /c schtasks /create /f /sc MINUTE /MO 5 /tn "MicrosoftEdgeAcModuleUpdateTask" /tr "<path> -project-mod"
If IdrInit.exe is executed as a non-admin user, Yokai creates a scheduled task, even if it already exists, named “MicrosoftTSUpdate” which executes IdrInit.exe every five minutes.
Upon execution, the malware first checks for the "-project-mod" argument and then establishes persistence via a scheduled task if the user is not a member of the Administrator's group: cmd.exe /c schtasks /create /f /sc MINUTE /MO 5 /tn "MicrosoftEdgeAcModuleUpdateTask" /tr "<path> -project-mod"
The shortcut files named in Thai... Translated, both documents are called “United States Department of Justice.pdf” and “Urgently, United States authorities ask for international cooperation in criminal matters.docx” respectively.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor dropped by the SnakeDisk USB worm in Mustang Panda activity targeting Thailand-based IP ranges.
Backdoor delivered via DLL side-loading in a campaign targeting Thai government officials.
Yokai is a backdoor delivered via USB worm (TONEDISK/WispRider), providing remote access and control to attackers.
A backdoor dropped by SnakeDisk that establishes a reverse shell for arbitrary command execution. It has overlaps with other Hive0154 backdoor families such as PUBLOAD/PUBSHELL and TONESHELL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.