Ecipekac, also known as DESLoader, SigLoader, and HEAVYHAND, is a multi-stage Windows malware loader associated with APT10 and the A41APT cyberespionage campaign targeting Japanese organizations and their overseas branches. It decrypts successive portable executable and shellcode stages and executes payloads directly in memory, reducing disk-based exposure. Delivered payloads include SodaMaster, P8RAT, FYAntiLoader, and Cobalt Strike shellcode; FYAntiLoader can subsequently load xRAT or QuasarRAT.
Ecipekac executes through DLL side-loading using legitimate applications, including Oracle Java Policy Tool and VMware utilities. It can retrieve encrypted payload data from modified Microsoft-signed DLLs whose signatures continue to validate. This technique abuses the exclusion of the PE Certificate Table from Authenticode hash calculations, allowing encrypted data to be stored without invalidating signature verification. Its layered decryption routines include XOR, custom DES, and AES, with implementation changes across variants. Samples also contain anti-analysis junk code and manipulated compilation timestamps.
In A41APT intrusions, Ecipekac was deployed after compromise of internet-facing systems, including exploitation of SSL-VPN vulnerabilities. Attackers established persistence through scheduled tasks that repeatedly launched legitimate applications to side-load the loader. Ecipekac supplies the execution framework for subsequent espionage payloads rather than independently providing their credential-stealing or remote-control capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign" is the reference for abuse of Oracle Java Platform SE 8 Policy Tool, policytool.exe.
Distinguish attack campaign that threat actor intrudes via internet-facing system, deploy malware such as SigLoader/Sodamaster...
2-1. DESLoader — Aka. SigLoader ▪ Loader file for DLL Side-Loading and files contain encrypted shellcode and payload. ▪ Decrypt multiple PEs and shellcodes sequentially in multiple stages. ▪ Finally, the payload is executed in memory.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Signed DLL with encrypted shellcode ... Legitimate file ... DLL Side-Loading
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated multilayered loader associated with APT10 and the A41APT campaign. Its referenced campaign is included as an example of DLL hijacking involving policytool.exe.
A multi-layer loader used by menuPass that loads and decrypts payloads, then loads FYAnti directly in memory to avoid writing files to disk.
Loader used long-term by A41APT; decryption process and command set were updated (per the presentation).
Enterprise New Software: ... Ecipekac
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.