LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1228: PUBLOAD

PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components.Citation2022 November_TrendMicro_Earth Preta_Toneshell_Pubload PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.Citation2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

EnterpriseS1228MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

PUBLOAD matters because it represents a Windows stager pattern: establish a foothold, place components in believable local directories such as C:\Users\Public or newly created staging paths, collect host details, persist, and communicate back to command and control. For leaders, the decision value is not just “malware exists,” but whether the organization can quickly prove what ran, where it staged files, what persistence was created, what host details left the environment, and whether follow-on tool transfer occurred.

Executive priority

Prioritize PUBLOAD as a readiness test for Windows endpoint visibility, egress monitoring, and incident response scoping. The ATT&CK relationships connect it to discovery, scheduled task persistence, command shell/WMI execution, obfuscation/compression, web/file-transfer based C2, and ingress tool transfer. That combination can affect business continuity by turning an initial host compromise into a harder-to-scope intrusion. Executives should ask whether SOC and IR teams can produce audit-ready evidence for endpoint process activity, task creation, suspicious staging directories, registry/service discovery, and outbound network sessions from affected hosts.

Technical view

PUBLOAD is a Windows malware object with no official ATT&CK detection text provided. Defensive validation should therefore be behavior-led using its mapped relationships: monitor creation and execution of files from public or newly created staging directories; correlate command shell, WMI, scheduled task, registry query, service/process/network discovery, and system information collection activity; and review outbound web or file-transfer protocol traffic that may impersonate legitimate services. Because the object is described as encrypting victim details with RC4 and communicating them to C2, network and host triage should focus on unusual outbound sessions following host discovery and persistence events rather than relying only on static signatures.

Likely telemetry

  • Windows endpoint process creation and command-line logs
  • File creation, modification, and execution events in C:\Users\Public and other newly created directories
  • Scheduled task creation and modification telemetry
  • WMI activity and command execution records
  • Windows Registry query activity

Detection direction

  • Validate correlations across staging location, execution, discovery, persistence, and outbound communication; single events such as C:\Users\Public file creation may be noisy without sequence context.
  • Tune for suspicious use of cmd.exe, WMI, schtasks, registry queries, service enumeration, and process/network discovery when performed by unusual parent processes or from uncommon directories.
  • Review outbound web and file-transfer protocol traffic from newly infected or rarely communicating endpoints, especially after local discovery activity.
  • Account for false positives from legitimate administration, software deployment, inventory tools, and help desk scripts; baselining approved management activity is important.
  • Because no official detection guidance is supplied, do not assume existing ATT&CK coverage maps detect PUBLOAD specifically; test detections against the mapped behaviors instead.

Mitigation priorities

  • Harden Windows endpoint execution controls around user-writable and public directories where feasible.
  • Restrict and monitor scheduled task creation, WMI usage, command shell execution, and registry/service discovery by non-administrative or unexpected processes.
  • Ensure endpoint detection, centralized logging, and network egress telemetry are retained long enough to reconstruct staging, persistence, discovery, and C2 timelines.
  • Apply least privilege and administrative tool governance to reduce abuse of legitimate Windows management features.
  • Use egress filtering and proxy/firewall review to limit unnecessary outbound web and file-transfer protocol paths from workstations and servers.
Additional notes and limits

ATT&CK identifies PUBLOAD as a stager observed installing in existing directories such as C:\Users\Public or creating new directories to stage malware and components. It is described as collecting victim host details, establishing persistence, encrypting victim details using RC4, and communicating those details back to C2. ATT&CK also notes prior use by the China-affiliated group Mustang Panda and reporting overlap where PUBLOAD is known as NoFive and the loader component may be identified as CLAIMLOADER in public reporting.

The supplied ATT&CK object has no official detection section and no malware-level tactics listed. The guidance above is derived from the official description, Windows platform field, external references, and supplied relationships to techniques. Local validation is required to determine whether telemetry exists, whether detections are enabled, and whether observed activity is malicious or legitimate administration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

PUBLOAD

PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components.Citation2022 November_TrendMicro_Earth Preta_Toneshell_Pubload PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.Citation2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
6d7e178c3ac50b02...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.