Description
PUBLOAD is a stager malware that installs itself into existing directories such as the Public user folder or creates new directories to stage its components. It collects victim host details, establishes persistence, encrypts the collected information with RC4, and reports it back to its operators, and China affiliated actors including Mustang Panda have leveraged it.
Stats
- First seen
- November 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
35 techniques across 8 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.015Compression
- T1027Obfuscated Files or Information
- T1027.015Compression
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1140Deobfuscate/Decode Files or Information
- T1205Traffic Signaling
- T1480Execution Guardrails
- T1480.001Environmental Keying
- T1574Hijack Execution Flow
- T1574.001DLL
- T1622Debugger Evasion
TA0007 Discovery
- T1007System Service Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1016System Network Configuration Discovery
- T1033System Owner/User Discovery
- T1049System Network Connections Discovery
- T1057Process Discovery
- T1082System Information Discovery
- T1124System Time Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1614System Location Discovery
- T1614.001System Language Discovery
- T1680Local Storage Discovery
TA0011 Command and Control
TA0010 Exfiltration
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Backdoor.Pubload |
| Win32.Trojan.Pubload |
