ATT&CKSoftwareCLAIMLOADER

CLAIMLOADER

S1236

Malware.View on attack.mitre.org

About this malware

CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be leveraged by Mustang Panda and was first observed utilized in 2021.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.007
Dynamic API Resolution

CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically.

T1036.005
Match Legitimate Resource Name or Location

CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software.

T1053.005
Scheduled Task

CLAIMLOADER has created scheduled tasks that execute the loader every five(5) minutes using `schtasks /F /Create /TN \"<fake_software_name>\" /SC minute /MO 5 /TR
\"C:\\ProgramData\\<path_to_exe> <hardcoded_argument>\`.

T1106
Native API

CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`.

T1140
Deobfuscate/Decode Files or Information

CLAIMLOADER has decoded its payload prior to execution.

T1204.002
Malicious File

CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments.

T1480.002
Mutual Exclusion

CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running.

T1547.001
Registry Run Keys / Startup Folder

CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1559.001
Component Object Model

CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface.

T1564.001
Hidden Files and Directories

CLAIMLOADER has modified file attributes to remain hidden to a standard user.

T1574.001
DLL

CLAIMLOADER has used a legitimately signed executable to execute a malicious payload within a DLL file.

Groups that use it1

Campaigns0

None recorded.

References2

  1. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA Open source
    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.
  2. IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025 Open source
    Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.