Ecipekac is a multi-layer loader malware family also referred to as DESLoader, SigLoader, and HEAVYHAND. It has been associated with the A41APT espionage campaign, which Kaspersky attributed to APT10 with high confidence. Reported activity dates to at least March 2019, and the malware was used after exploitation of SSL-VPN vulnerabilities to deploy follow-on payloads including SodaMaster, P8RAT, FYAnti, and QuasarRAT.
Its core role is to load and decrypt target payloads. In one described execution chain, SigLoader decrypts and loads the first payload, FYAnti, directly in memory. FYAnti then decrypts an embedded .NET module and reflectively loads it using the CppHostCLR technique, enabling execution without extracting the assembly to disk. Related detection-relevant behavior includes loading CLR components such as mscor.dll, mscoree.dll, and clr.dll into unusual host processes.
The malware has also been described as abusing the legitimate application policytool.exe to load a malicious DLL, indicating DLL side-loading or proxy execution tradecraft. Separately, Ecipekac has been reported using a valid legitimate digital signature to evade detection. The associated APT10/menuPass activity targeted sectors including healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, SigLoader is a multi-layer loader that loads and decrypts the target payload. Eventually, SigLoader will load the first payload, FYAnti, in memory.
They first explained that the decryption process and commands of SigLoader and SoadMaster, the malware A41APT has long used, were updated.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-layer loader used by menuPass that loads and decrypts payloads, then loads FYAnti directly in memory to avoid writing files to disk.
Loader used long-term by A41APT; decryption process and command set were updated (per the presentation).
Enterprise New Software: ... Ecipekac
Multi-layered loader used after SSL-VPN exploitation to deploy mostly fileless payloads/implants in an espionage campaign attributed to APT10.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.