Pisloader is a Windows remote-access trojan and variant of HTTPBrowser used by the China-linked Wekby threat group, also known as APT18 and Dynamite Panda. It was identified in a 2016 cyberespionage campaign targeting a U.S.-based organization. Its supported commands include collecting the victim's IP address and spawning a command shell.
Pisloader uses DNS tunneling for command-and-control communication, periodically sending beacons to a hardcoded server and receiving Base32-encoded commands through DNS TXT records. It validates response formatting and ignores replies that do not match its expected structure. This use of DNS helps disguise malicious communications within ordinary network traffic. The payload also employs return-oriented programming techniques for obfuscation.
Observed deployment involved malware delivered over HTTP and a dropper that decrypted embedded payload data with single-byte XOR, wrote the payload to disk, and executed it. Persistence is established through a Windows Registry-based autorun mechanism configured using the Windows command shell.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Wekby APT group targeted US-based organizations using malware dubbed ‘pisloader,’ described as a variant of the HTTPBrowser RAT that uses DNS requests for command-and-control communications.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
DarkTortilla can use cmd.exe to add registry keys for persistence. HeartCrypt can use the reg add command via cmd.exe for Registry modification. Ryuk has used cmd.exe to create a Registry entry to establish persistence.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
ATT&CK Ⓡ does not have an explicit technique assigned for DNS Tunneling; instead, it identifies this technique as a sub-technique of Command and Control Over Application Layer Protocol, described as follows: “Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.”
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Includes a command to collect victim IP addresses.
Backdoor with a command to collect the victim's IP address.
Malware that establishes persistence through a Registry Run key.
Malware whose command-and-control server responses are Base32-encoded.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.