PUBLOAD
S1228 · Windows
PUBLOAD is a stager malware that has been observed installing itself in existing directories such as C:\Users\Public or creating new directories to stage the malware and its components. PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda.
PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.
ATT&CK S1228
Sigma rules0
YARA rules0
Live IOCs0