PUBLOAD is a Windows malware family associated with the China-aligned espionage ecosystem commonly tracked as Mustang Panda, Earth Preta, Hive0154, ITG27, and Stately Taurus. It is most consistently described as a downloader or stager used to establish initial control on a compromised host, communicate with command-and-control infrastructure, and retrieve or launch follow-on payloads including shellcode and additional malware such as PlugX, TONESHELL, and FDMTP. Reporting also describes closely related tooling under the name PUBSHELL and notes architectural similarities with TONESHELL and other malware in the same operational cluster.
PUBLOAD is frequently deployed through spearphishing campaigns using decoy documents and weaponized archives, including lures themed around government, diplomatic, and geopolitical subjects in the Asia-Pacific region. In multiple campaigns, operators embedded cloud-storage links such as Google Drive links in decoy documents to deliver password-protected archives. It has also been observed in worm-enabled intrusion chains where a removable-drive propagation component delivered PUBLOAD into victim environments. Execution commonly relies on DLL sideloading through legitimate signed executables, and operators have also used valid digital signatures and certificates as part of broader defense-evasion tradecraft.
Once active, PUBLOAD functions as a main control utility or staging implant. Observed variants perform host and network reconnaissance, including discovery of installed antivirus products, system configuration, users, processes, network settings, and routing information. It can execute commands, download shellcode or secondary payloads, launch additional tools, and support collection workflows by invoking legitimate utilities for archiving and transfer. In espionage operations attributed to Mustang Panda and related clusters, PUBLOAD has been used to run collection tooling, compress documents with RAR, and exfiltrate data using command-line transfer utilities or FTP-based workflows. Some variants maintain persistence through autorun-style mechanisms and scheduled tasks.
Operational reporting links PUBLOAD to campaigns targeting government, diplomatic, and critical-sector organizations, especially in Asia-Pacific, including energy-sector and Southeast Asian government-focused intrusions. Infrastructure and tradecraft overlaps also connect PUBLOAD to Bookworm-related activity and to broader Mustang Panda malware evolution from long-running PlugX operations toward newer families such as TONESHELL, LOTUSLITE, SnakeDisk, and FDMTP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Associated malware families such as Toneshell, Pubload and Claimloader undergo frequent updates that enhance ITG27’s adaptability within their target environments.
Associated malware families such as Toneshell, Pubload and Claimloader undergo frequent updates that enhance ITG27’s adaptability within their target environments.
UNK_SteadySplit is a user of the custom TONESHELL and PUBLOAD malware families, alongside multiple other first-stage malware families delivered in phishing campaigns.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in the malware/tools list without further discussion in the content.
Named as part of ITG27's malware arsenal and described as an associated malware family undergoing frequent updates, but no technical behavior is detailed in this reference.
A downloader previously used to distribute FDMTP as a secondary payload.
Loader/downloader families linked to the same Mustang Panda operational ecosystem and architecturally similar to TONESHELL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.