SigLoader, also known as DESLoader, Ecipekac, and HEAVYHAND, is a multi-stage Windows malware loader used in targeted intrusion campaigns, particularly those associated with the A41APT cluster and widely linked in public reporting to APT10/menuPass. It is designed to decrypt and execute additional payloads in memory while minimizing on-disk artifacts and evading detection through abuse of legitimate signed software components.
A defining characteristic of SigLoader is its use of DLL side-loading with legitimate executables to launch malicious code. Observed execution chains have abused trusted applications such as policytool.exe and other signed binaries to load a malicious DLL. In multiple cases, SigLoader also abused Microsoft-signed DLLs that had been tampered with by appending or embedding malicious data in areas that do not invalidate Windows signature verification, allowing the files to continue appearing legitimately signed. This technique supports defense evasion by blending malicious content with trusted signed files.
SigLoader operates as a layered loader. It reads encrypted data from a companion file or from embedded regions of a signed DLL, then performs staged decryption and reconstruction of additional loader components and payloads. Reported implementations have used combinations of XOR, custom DES, AES, and in some variants RSA or RC4-related routines. The loader can decrypt multiple PE files and shellcode stages sequentially, culminating in in-memory execution of the final payload. Some variants evolved over time, including changes to encryption identifiers and AES mode selection.
The malware has been used to deliver a range of follow-on payloads, including SodaMaster, P8RAT, FYAnti, xRAT, GreetCake, DelfsCake, Cobalt Strike shellcode or Beacon-related stages, and webshell components such as Jackpot. Several of these payloads are memory-resident or fileless, reinforcing SigLoader’s role as a stealth-oriented staging framework for espionage operations. Associated campaigns have targeted organizations in Japan and overseas branches of Japanese companies, with compromises often beginning through exploitation of internet-facing systems such as SSL-VPN appliances and Microsoft Exchange Server rather than phishing.
SigLoader is best understood as a modular intrusion loader used after initial compromise to establish execution, decrypt embedded stages, and hand off to espionage tooling. Its combination of DLL side-loading, signed-file abuse, staged decryption, and reflective or in-memory payload execution makes it a notable example of defense-evasive loader tradecraft in China-linked cyber-espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2020年7月ごろから、Microsoft社のデジタル署名(コードサイニング証明書)されたDLLファイルを悪用するマルウェア「SigLoader」が使われた標的型攻撃を複数確認しています。
Distinguish attack campaign that threat actor intrudes via internet-facing system, deploy malware such as SigLoader/Sodamaster...
2-1. DESLoader — Aka. SigLoader ▪ Loader file for DLL Side-Loading and files contain encrypted shellcode and payload. ▪ Decrypt multiple PEs and shellcodes sequentially in multiple stages. ▪ Finally, the payload is executed in memory.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Signed DLL with encrypted shellcode ... Legitimate file ... DLL Side-Loading
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-layer loader used by menuPass that loads and decrypts payloads, then loads FYAnti directly in memory to avoid writing files to disk.
Loader used long-term by A41APT; decryption process and command set were updated (per the presentation).
Enterprise New Software: ... Ecipekac
Malware that decrypts fileless loader modules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.