CLAIMLOADER has utilized XOR-encrypted API names and native APIs of LdrLoadDll() and LderGetProcedureAddress() to resolve imports dynamically.34
tool
CLAIMLOADER S1236
- Type
- malware
- Platform
- Windows
- Created
- 12 September 2025
- Last modified
- 21 October 2025
CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be leveraged by Mustang Panda and was first observed utilized in 2021.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1236
CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in C:\ProgramData\ and the use of legitimate looking names of software.5
CLAIMLOADER has created scheduled tasks that execute the loader every five(5) minutes using schtasks /F /Create /TN \"<fake_software_name>\" /SC minute /MO 5 /TR
\"C:\\ProgramData\\<path_to_exe> <hardcoded_argument>\.6
CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion.78 CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including GetDC() and EnumFontsW().7 CLAIMLOADER established persistence by utilizing the API SHSetValue().7 CLAIMLOADER has utilized APIs with callback functions such as EnumpropsExW, EnumSystemLanguageGroupsA, and EnumCalendarInfoExW.8
CLAIMLOADER has decoded its payload prior to execution.1213
CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments.14
Standing S1236
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
51st percentile · 51% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
32nd percentile · 68% of 825 ATT&CK software entries have more tactics spanned.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
48th percentile · 52% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1236
371 distinct rules cover the 11 techniques recorded for this tool. The 378 technique-to-rule mappings resolve to 371 distinct rules, because one rule can cover several techniques. 288 Sigma · 83 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org