PubLoader is a shellcode-based malware stage used in a June 2025 Mustang Panda campaign identified by IBM X-Force that targeted the Tibetan community for political reasons. In the observed infection chain, victims received a phishing-delivered ZIP archive containing a decoy executable named "Voice for the Voiceless Photos.exe" and a hidden DLL, "libjyy.dll." The decoy used DLL side-loading to load the hidden DLL, identified as ClaimLoader, which checked for the command-line argument "Licensing." When the correct argument was present, ClaimLoader decrypted and executed PubLoader shellcode. If the argument was absent or incorrect, ClaimLoader established persistence by creating "C:\ProgramData\AdobeLicensingPlugin," moving the decoy to "C:\ProgramData\AdobeLicensingPlugin\WF_Adobe_licensing_helper.exe," moving the DLL to "C:\ProgramData\AdobeLicensingPlugin\NewUI.dll," creating a Run registry key to launch the helper with the "Licensing" argument at startup, and creating a scheduled task named "AdobeExperienceManager" to run every two minutes. ClaimLoader allocated executable memory with VirtualAlloc, copied decrypted shellcode into it, and executed it via an EnumFontsW callback. The extracted PubLoader shellcode resolved APIs using PEB walking and ROR13 API hashing, then collected device information and sent it to a command-and-control server. High-confidence associated artifacts in this chain include the filenames "Voice for the Voiceless Photos.exe," "libjyy.dll," "WF_Adobe_licensing_helper.exe," and "NewUI.dll," the directory "C:\ProgramData\AdobeLicensingPlugin," the scheduled task name "AdobeExperienceManager," and the command-line argument "Licensing."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
If the correct argument is detected, Claimloader will follow its code flow for decryption, injection, and Publoader execution.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
VirtualAlloc is an extremely common function for allocating buffers for shellcode... After copying the shellcode to the previously allocated buffer... the offset of this buffer will be used as an argument for the EnumFontsW function call, which, when called, will execute the shellcode by abusing the API’s Callback mechanism.
the developers likely implemented API Hashing to dynamically load APIs in an obfuscated manner... Publoader also implements a long API loading function through API Hashing | all strings encrypted by this algorithm refer to APIs that will be dynamically loaded... parse the ntdll.dll module to load the LdrLoadDll API... followed by the decrypted API being loaded via the LdrGetProcedureAddress API.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used in a Mustang Panda-attributed campaign; delivered via phishing and DLL side-loading to initiate execution of subsequent components.
A next-stage shellcode loader executed by Claimloader. It uses PEB walking and ROR13 API hashing to resolve DLLs and APIs dynamically, then collects information from the device and sends it to a command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.