PUBLOAD is a Windows malware family used as a first-stage loader and downloader in China-aligned cyber espionage operations, most consistently associated with Mustang Panda, also tracked as Earth Preta, Stately Taurus, and Hive0154. It has been active since at least early 2022 and has been used primarily against government and related entities in the Asia-Pacific region, including diplomatic, military, police, foreign affairs, executive, welfare, and education targets. PUBLOAD has also appeared in broader Southeast Asian intrusion activity and in campaigns linked to Stately Taurus infrastructure overlaps.
PUBLOAD is commonly deployed through DLL sideloading chains that abuse legitimate signed executables to load a malicious DLL. It has also been delivered through spearphishing campaigns, including weaponized archives and decoy documents containing links to cloud-hosted payloads such as Google Drive. In worm-enabled intrusion chains, removable-drive propagation has been used to introduce PUBLOAD into victim environments.
Functionally, PUBLOAD acts as stager malware and a control component for follow-on activity. It communicates with command-and-control infrastructure to retrieve additional payloads, including shellcode-based second stages and other malware families such as PlugX and FDMTP. Reported variants support downloading shellcode over HTTP POST as well as raw TCP traffic designed to resemble TLS. Some variants use spoofed or Windows Update-themed network patterns to blend malicious traffic with legitimate-looking activity.
On compromised hosts, PUBLOAD has been observed performing reconnaissance and security software discovery using native Windows utilities and WMI queries. It can execute operator-directed tasks, deliver supplementary tools, collect files for staging with archiving utilities, and exfiltrate data using command-line transfer tools and FTP-based workflows. In some campaigns it served as the main orchestration tool for collection and exfiltration operations.
PUBLOAD also supports persistence and defense evasion. Observed techniques include scheduled-task creation and autorun-style persistence, as well as the use of valid digital signatures or trusted executable sideloading chains to reduce detection. Across reporting, PUBLOAD is consistently characterized as part of the evolving Mustang Panda malware ecosystem alongside TONESHELL, COOLCLIENT, LOTUSLITE, SnakeDisk, and related tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PUBLOAD was used as the main control tool for most of the campaign and to perform various tasks, including the execution of tools such as RAR for collection and curl for data exfiltration.
UNK_SteadySplit is a user of the custom TONESHELL and PUBLOAD malware families, alongside multiple other first-stage malware families delivered in phishing campaigns.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
HIUPAN spreads through removable drives to deliver PUBLOAD.
Throughout mid-2025, X-Force observed several weaponized archives uploaded to VirusTotal from Singapore and Thailand... The archive "CallNotes.zip" discovered in September was downloaded from Box Cloud Storage through a link in a PDF lure impersonating the Myanmar Ministry of Foreign Affairs.
PUBLOAD has its own installation routine, which includes copying all components to its install path and creating autorun registry entry and a scheduled task.
facilitate two active reverse shells in parallel... Yokai, a backdoor that sets up a reverse shell to execute arbitrary commands.
Similar to previous variants, a reverse shell is set up using anonymous pipes connected to stdin and stdout handles of a new cmd.exe process... Toneshell operators can write string data to the pipe using the correct shell_id and execute arbitrary commands on the machine.
Victims will receive and interact with a decoy document containing a Google Drive link and a corresponding password instead of an archive download link embedded in the email.
The document lures users into downloading a malicious password-protected archive with the embedded link. The files can then be extracted inside via the password provided in the document.
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The HTTP request includes www.asia.microsoft.com within the host field as an attempt to masquerade as a legitimate request associated with the Windows operating system. Also, the URL pattern seen in these HTTP requests appears to be an attempt to mimic legitimate URLs accessed by Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The TONEINS malware, libcef.dll, will decrypt this file with a single byte in XOR operations, find the PE header, and drop the payload
This sophisticated malware utilizes Dynamic Link Library (DLL) sideloading techniques to execute malicious payloads... In a notable instance, the malware exploited a legitimate executable signed by an automation organization to load a malicious payload identified as BrMod104.dll.
Commands like ipconfig and netsh are used to discover network configuration.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
The most recent Pubload variant has undergone minor changes and now supports decoy C2 servers and downloading shellcode payloads via HTTP POST in addition to raw TCP imitating TLS traffic.
The decrypted payload contains another payload that is XOR-encrypted... After this is decrypted, there is yet another final backdoor payload
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader previously used to distribute FDMTP as a secondary payload.
Loader/downloader families linked to the same Mustang Panda operational ecosystem and architecturally similar to TONESHELL.
Referenced only in infrastructure comparison to support attribution, via a previously identified C2 server associated with Mustang Panda.
Referenced as part of Mustang Panda's evolving malware/tooling ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.