Description
HUI Loader is a custom DLL loader used since at least 2015 by China based threat groups including Cinnamon Tempest and menuPass to deploy malware on compromised hosts. Researchers have observed it loading SodaMaster, PlugX, Cobalt Strike, Komplex, and several strains of ransomware.
Stats
- First seen
- April 2022
- Last seen
- September 2026
Also known as
HuiLoaderHuiloader
MITRE ATT&CK techniques
3 techniques across 2 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Trojan.Huiloader |
| Win64.Trojan.Huiloader |
| Win64.Trojan.HuiLoader |