NEXLOAD is a custom downloader associated with China-aligned intrusion activity and used to deploy the HOLODONUT modular .NET backdoor. It has been observed in activity clusters tied to the broader PeckBirdy ecosystem, particularly SHADOW-VOID-044, which targeted Chinese gambling-related organizations through compromised websites and fake software update lures. NEXLOAD functions as a lightweight first-stage launcher that retrieves a remote payload, decrypts it with XOR, and executes it in memory via an EnumWindows callback, reducing on-disk artifacts and supporting stealthy delivery of follow-on malware. In observed operations, the payload delivered through NEXLOAD was HOLODONUT, a .NET backdoor that incorporates additional defense-evasion measures such as AMSI and ETW interference and in-memory execution of .NET assemblies. High-confidence reporting supports NEXLOAD’s role as a downloader rather than a full-featured backdoor, with its primary purpose being covert retrieval and execution of second-stage malware on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
To execute HOLODONUT, the threat actors deployed a customized simple downloader used to retrieve the payload from the remote server downloader that we tracked as NEXLOAD... During the first initiation, the downloader will connect to the C&C server and download the backdoor module.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom downloader used to fetch HOLODONUT payloads from a remote server. It sends a distinctive initial string format during first connection, after which the payload is decrypted and executed.
Custom downloader/loader used to deploy the HOLODONUT modular .NET backdoor.
Simple downloader used to launch the HOLODONUT modular .NET backdoor.
Downloader used to deploy HOLODONUT in the described campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.