Ps2dllLoader is a loader used by the espionage threat actor Unfading Sea Haze in operations targeting primarily government and military organizations in South China Sea countries. Bitdefender reported it was used in earlier campaigns, alongside .NET SharpJSHandler variants, to load .NET or PowerShell malicious code directly into memory as part of a fileless attack chain. The malware supported in-memory execution of payloads and was later replaced by a newer fileless mechanism based on MSBuild and remote SMB shares. A 2024 update to Ps2dllLoader reportedly added AMSI and ETW patching for defense evasion. In the observed campaigns, Ps2dllLoader formed part of a broader espionage toolset that included multiple Gh0st RAT-derived families and custom collection tooling. The content does not provide standalone indicators of compromise specific to Ps2dllLoader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In earlier attacks, the hacker also used Ps2dllLoader, a tool that loads .NET or PowerShell code into memory...
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader used to execute .NET or PowerShell code directly in memory.
A loader used to execute payloads in memory in support of SharpJSHandler during Unfading Sea Haze operations.
In-memory (fileless) loader used to execute .NET/PowerShell payloads; later versions add AMSI/ETW patching for defense evasion. Report notes a shift toward MSBuild/remote SMB execution replacing it in some cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.