HUI Loader is a custom Windows malware loader associated with multiple China-nexus intrusion sets and espionage operations, and has also appeared in incidents linked to ransomware deployment. It is commonly used as an intermediate execution component that side-loads through legitimate applications vulnerable to DLL search order hijacking, decrypts or stages an encrypted payload blob, and launches follow-on malware in memory. Reported payloads include Cobalt Strike Beacon and SodaMaster, and the loader has been observed injecting payloads into trusted Windows processes such as mstsc.exe and svchost.exe.
A characteristic deployment pattern uses a three-part chain consisting of a legitimate executable, a malicious DLL loader, and an encrypted data blob. Variants have been distributed alongside legitimate software components from products such as Microsoft Edge, Adobe Creative Cloud, McAfee VirusScan, and other signed applications, enabling execution through DLL side-loading and helping the malware blend with normal software activity. In some campaigns, HUI Loader was delivered through trojanized software packages; in others, operators deployed it post-compromise on already accessed systems.
HUI Loader is notable for defense-evasion functionality, including the ability to disable or bypass Windows Event Tracing for Windows and the Antimalware Scan Interface. Its operational role is primarily post-compromise staging and in-memory execution rather than standalone persistence or command-and-control. Public reporting has linked its use to campaigns targeting Japanese organizations, Southeast Asian government and gambling-sector entities, and to activity overlapping with groups and clusters such as APT10, APT41-linked operations, BRONZE STARLIGHT, and Cluster Charlie in Crimson Palace. Because Chinese threat actors frequently share tooling, HUI Loader is best understood as a shared loader used across multiple related operators rather than a uniquely actor-specific implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered another loader used for loading SodaMaster in 2021 ... Named after string "HUIHWASDIHWEIUDHDSFSFEFWEFEWFDSGEFERWGWEEFWFWEWD"
We discovered another loader used for loading SodaMaster in 2021 ... Named after string "HUIHWASDIHWEIUDHDSFSFEFWEFEWFDSGEFERWGWEEFWFWEWD"
The malicious DLLs libcef.dll, msedge_elf.dll, and LockDown.dll distributed by agentupdate_plugins.exe and AdventureQuest.exe are HUI Loader variants.
The malicious DLLs libcef.dll, msedge_elf.dll, and LockDown.dll distributed by agentupdate_plugins.exe and AdventureQuest.exe are HUI Loader variants.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution Flow of HUI Loader ... XOR decode & code injection ... svchost.exe
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Signed DLL with encrypted shellcode ... Legitimate file ... DLL Side-Loading
agentupdate_plugins.exe and AdventureQuest.exe deploy .NET executables based on the SharpUnhooker tool, which download second-stage data from Alibaba buckets hosted at agenfile.oss-ap-southeast-1.aliyuncs[.]com and codewavehub.oss-ap-southeast-1.aliyuncs[.]com. The second-stage data is stored in password-protected zip archives.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom loader used to de-obfuscate and stage encrypted payloads; in this case it unpacked and injected a Cobalt Strike reflective loader and beacon.
A custom malware loader used to inject a Cobalt Strike beacon into mstsc.exe for stealthy execution.
A custom malware loader used to inject a Cobalt Strike Beacon into mstsc.exe.
A custom malware loader used to inject a Cobalt Strike beacon into mstsc.exe, helping the threat actor deploy payloads while blending into legitimate processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.