ATT&CKSoftwareHUI Loader

HUI Loader

S1097

Malware.View on attack.mitre.org

About this malware

HUI Loader is a custom DLL loader that has been used since at least 2015 by China-based threat groups including Cinnamon Tempest and menuPass to deploy malware on compromised hosts. HUI Loader has been observed in campaigns loading SodaMaster, PlugX, Cobalt Strike, Komplex, and several strains of ransomware.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1140
Deobfuscate/Decode Files or Information

HUI Loader can decrypt and load files containing malicious payloads.

T1574.001
DLL

HUI Loader can be deployed to targeted systems via legitimate programs that are vulnerable to DLL search order hijacking.

T1685
Disable or Modify Tools

HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions.

Groups that use it2

Campaigns0

None recorded.

References1

  1. SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022 Open source
    Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.