PUBLOAD has modified HTTP POST requests to resemble legitimate communications.34 PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.5
tool
PUBLOAD S1228
- Type
- malware
- Platform
- Windows
- Created
- 4 August 2025
- Last modified
- 12 May 2026
PUBLOAD is a stager malware that has been observed installing itself in existing directories such as C:\Users\Public or creating new directories to stage the malware and its components.[1] PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.[2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1228
PUBLOAD has leveraged tasklist to gather running services on victim host.6
PUBLOAD has queried Registry values to identify software using reg query.7
PUBLOAD has obtained information about local networks through the ipconfig /all command.8
PUBLOAD has identified internet connectivity details through commands such as tracert -h 5 -4 google.com and curl http://myip.ipip.net.9
PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging netsh wlan show profiles, netsh wlan show interface, and netsh wlan show. 10
Standing S1228
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
96th percentile · 96% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
89th percentile · 89% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
29th percentile · 71% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1228
922 distinct rules cover the 35 techniques recorded for this tool. The 1002 technique-to-rule mappings resolve to 922 distinct rules, because one rule can cover several techniques. 693 Sigma · 229 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org