hcdLoader

S0071

Malware.View on attack.mitre.org

About this malware

hcdLoader is a remote access tool (RAT) that has been used by APT18.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1059.003
Windows Command Shell

hcdLoader provides command-line access to the compromised system.

T1543.003
Windows Service

hcdLoader installs itself as a service for persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Dell Lateral Movement Open source
    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.