Netskope Threat Labs

PUBLOAD

ATP Sandbox Adv. Heuristics

PUBLOAD is a stager malware that installs itself into existing directories such as the Public user folder or creates new directories to stage its components. It collects victim host details, establishes persistence, encrypts the collected information with RC4, and reports it back to its operators, and China affiliated actors including Mustang Panda have leveraged it.

First seen
November 2022
Last seen
September 2026

35 techniques across 8 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol
    • T1048.003Exfiltration Over Unencrypted Non-C2 Protocol

TA0112 Defense Impairment

Alert Name
Win32.Backdoor.Pubload
Win32.Trojan.Pubload