Skip to main content
Mallory
Back to malware
MalwareUsed by 5 actors

Hypnosis Loader

Hypnosis Loader is a novel DLL loader observed by Palo Alto Networks Unit 42 in a 2025 cyberespionage campaign targeting a government organization in Southeast Asia. It was used by activity cluster CL-STA-1049, which overlaps with the publicly tracked China-aligned group Unfading Sea Haze. The malware was deployed through DLL sideloading or DLL proxy sideloading, including abuse of a legitimate Bitdefender executable (seccenter.exe) loading a malicious version.dll from C:\Program Files\Common Files\Bitdefender\SetupInformation\version.dll. Its role in the intrusion was to stealthily install or deploy FluffyGh0st RAT as a follow-on payload. Unit 42 reported this loader as a stealthy, newly identified component in a broader operation involving multiple China-linked clusters seeking long-term persistent access to sensitive government networks and data exfiltration. High-confidence related indicators mentioned in the reporting include the malicious version.dll SHA256 9d7c8d3bc4ac108fb2602424a1f4918c051c2443f0526bbb2c970c8e57dbd90d, and an assessed final payload bdusersy.dll that communicated with webmail.rpcthai[.]com and was plausibly FluffyGh0st.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Mustang Panda

Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.

via scworldscworld.com
CL-STA-1048

Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.

via scworldscworld.com
CL-STA-1049

Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.

via scworldscworld.com
Unfading Sea Haze

Cluster CL-STA-1049 used a stealthy “Hypnosis” DLL loader to deploy FluffyGh0st RAT via DLL sideloading with a legitimate Bitdefender executable.

via security affairssecurityaffairs.com
Crimson Palace

Cluster CL-STA-1049 used a stealthy “Hypnosis” DLL loader to deploy FluffyGh0st RAT via DLL sideloading with a legitimate Bitdefender executable.

via security affairssecurityaffairs.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1129Shared ModulesEvidence1
TacticExecution

These alerts highlighted a DLL sideloading attack that used a legitimate Bitdefender executable, seccenter.exe.

T1055Process InjectionEvidence1

The loader injects itself, maintains execution, decrypts, and loads the final payload

Stealth

2 techniques
T1055Process InjectionEvidence1

The loader injects itself, maintains execution, decrypts, and loads the final payload

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

ClaimLoader then uses an XOR key to decrypt an embedded shellcode payload and executes the shellcode... After patching the DLL's host process, Hypnosis loader creates a new thread to decrypt the name of the final payload (bdusersy.dll) with an RC4 key.

T1568Dynamic ResolutionEvidence1

The base domain rpcthai[.]com appears to be used for the website of a legitimate Thai-based company, which implies that attackers hijacked the domain and created webmail.rpcthai[.]com to act as a C2 server.

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.