MemLoad is a Kimsuky-associated loader malware in the PebbleDash cluster, observed in multiple versions during 2025 and used in attack chains targeting primarily South Korean users and organizations. It appears as the intermediate stage between a small dropper and the final HttpTroy backdoor. Reported delivery includes spear-phishing attachments disguised as documents, with droppers observed in JSE, PIF, SCR, and EXE formats; in one documented case, a ZIP lure masquerading as a VPN invoice contained an SCR dropper that installed MemLoad. MemLoad performs anti-VM checks and reconnaissance to assess victim value, establishes persistence via scheduled tasks including ChromeCheck or EdgeCheck, and in one observed variant recreated a scheduled task named AhnlabUpdate that executed the DLL via regsvr32.exe /s on a one-minute interval. It downloads an additional payload from C2, decrypts it with RC4 using the key #RsfsetraW#@EsfesgsgAJOPj4eml;, and reflectively loads it into memory by invoking the exported function hello. The downloaded payload was identified as the HttpTroy backdoor; one reported HttpTroy C2 was file.bigcloud.n-e[.]kr/index.php, and another Kimsuky chain using Memload_V3 led to HttpTroy communicating with load[.]auraria[.]org/index.php. Reported mutexes in that chain were a:fnjiuygredfgbbgfcvhutrv and u:fnjiuygredfgbbgfcvhutrv. The malware is associated with North Korean threat actor Kimsuky, also tracked as APT43 and Ruby Sleet, and is part of campaigns mainly targeting South Korean public- and private-sector entities, with broader PebbleDash activity also observed against defense-related targets in Brazil and Germany.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MemLoad downloads httpTroy Since early 2025, we have observed several versions of MemLoad... Kimsuky leverages MemLoad to evade detection of its final backdoor and to carefully assess the value of targeted systems through anti-VM checks and reconnaissance.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Reger Dropper (.SCR) and Pidoc Dropper (.PIF) also contain benign lure files and malicious payloads that, in both cases, are encrypted using XOR operations... Pidoc Dropper is fully obfuscated using dummy data and encrypted strings.
These attachments often consist of compressed files containing droppers in formats such as .JSE, .EXE, .PIF, or .SCR. The filenames are consistent with the message content and are meant to convince the recipient to open the attachment.
Ultimately, the malicious payload is executed via command-line instructions such as regsvr32.exe /s [file path]
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MemLoad is a loader used in the Kimsuky attack chain to load the HttpTroy backdoor into memory, aiding in stealth and anti-analysis by avoiding disk writes.
Stage-1 component that establishes persistence via a scheduled task (“AhnlabUpdate”) executing regsvr32, then decrypts (RC4) and reflectively loads the final payload into memory and executes it via an exported function.
A loader used by Kimsuky to evade detection and assess victim systems. It creates a flag file, generates an ID based on privilege level, establishes persistence via scheduled tasks, downloads an additional payload from C2, decrypts it with RC4, and reflectively loads it into memory. The downloaded payload is httpTroy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.