HIUPAN, also known as U2DiskWatch and sometimes associated with the closely related USBFect lineage, is a Windows USB-propagating worm used in China-aligned espionage operations, most notably by Mustang Panda, also tracked as Earth Preta, Stately Taurus, MISTCLOAK, and Hive0154. It is designed to spread through removable drives by copying its components to USB media and leaving a visible lure executable intended to trick users into launching the infection chain. Execution commonly relies on DLL side-loading through a legitimate executable, after which HIUPAN installs itself on the host, establishes persistence through a Run key, and modifies Windows Explorer settings so hidden files, protected operating system files, and file extensions are not shown to the user, reducing the chance of discovery.
HIUPAN has been used as a propagation mechanism for follow-on payloads rather than solely as a standalone access tool. Documented campaigns show it delivering PUBLOAD and related components into victim environments, including government and government-adjacent targets in the Asia-Pacific region and operations affecting Taiwan and a Southeast Asian government. The malware periodically checks whether its associated payload is running and can relaunch it if needed, supporting durable post-compromise access. Reporting also links HIUPAN variants to removable-media-based lateral spread, including scenarios intended to bridge segmented or air-gapped environments.
Operationally, HIUPAN combines social engineering, USB propagation, persistence, and defense evasion. Its use of legitimate executables for DLL side-loading and its concealment of malicious artifacts on disk are consistent with Mustang Panda tradecraft. In observed intrusion sets, HIUPAN has served as an enabling worm for broader espionage activity involving backdoors, loaders, reconnaissance, file collection, and exfiltration performed by downstream malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Preta employed a variant of the worm HIUPAN to propagate PUBLOAD into their targets' networks via removable drives.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
Attackers deployed numerous malware families, including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Examples include: "Sandworm Team leveraged Microsoft Office attachments which contained malicious macros..."; "Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs"; "Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files."
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family used in a 2025 China-linked cyber campaign against a Southeast Asian government to help achieve persistent access and exfiltrate sensitive data.
A malware family closely related to USBFect; referenced as part of lateral spread via removable media in the campaign.
USB-based malware used to deliver the PUBLOAD backdoor.
The “Stately Taurus” cluster involved tools including HIUPAN, USBFect, PUBLOAD (spread via USB), and CoolClient variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.