LuciLoad is a C++ malware loader used by the China-aligned threat activity cluster UnsolicitedBooker. It has been observed in phishing-led intrusion chains targeting telecommunications companies in Kyrgyzstan and Tajikistan, and is associated with broader UnsolicitedBooker activity affecting organizations in Asia, Africa, and the Middle East, including prior targeting in Saudi Arabia. In observed campaigns, victims received phishing emails containing malicious Microsoft Office documents or links to decoy documents; when opened and macros were enabled, the documents dropped LuciLoad, which then delivered the LuciDoor backdoor. Decoy content included telecom-related tariff plan documents. The loader’s primary documented role is staging and deploying LuciDoor. LuciDoor, the payload delivered by LuciLoad, is described as communicating with a command-and-control server, collecting basic system information, exfiltrating it in encrypted form, executing commands via cmd.exe, writing files to the system, and uploading files. Related reporting also notes UnsolicitedBooker’s use of rare Chinese-origin tools, tactical overlaps with the Space Pirates cluster, and in at least one case the use of a compromised router as command-and-control infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When opened, these documents trigger macros that deploy malware loaders like LuciLoad or MarsSnakeLoader, which then deliver the respective backdoors.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader delivered via malicious Office macros; used to deliver the LuciDoor backdoor.
C++ loader dropped by malicious Office macros to deliver the LuciDoor backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.