PUBLOAD

S1228

Malware.View on attack.mitre.org

About this malware

PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components. PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.

T1007
System Service Discovery

PUBLOAD has leveraged `tasklist` to gather running services on victim host.

T1012
Query Registry

PUBLOAD has queried Registry values to identify software using `reg query`.

T1016
System Network Configuration Discovery

PUBLOAD has obtained information about local networks through the `ipconfig /all` command.

T1016.001
Internet Connection Discovery

PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`.

T1016.002
Wi-Fi Discovery

PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`.

T1027
Obfuscated Files or Information

PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm.

T1027.015
Compression

PUBLOAD has been delivered as compressed files within ZIP files to victims.

T1033
System Owner/User Discovery

PUBLOAD has obtained the username from an infected host.

T1036.005
Match Legitimate Resource Name or Location

PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe.

T1047
Windows Management Instrumentation

PUBLOAD has used `wmic` to gather information from the victim device.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site.

T1049
System Network Connections Discovery

PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather information on network connections.

T1053.005
Scheduled Task

PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...`

T1057
Process Discovery

PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running.

View all 35 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload Open source
    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.
  2. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA Open source
    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.