#PUBLOAD
Chinese hackers exploit Tibetan cultural events to deploy PubLoad malware via spear-phishing. Stay vigilant against sophisticated cyber threats. #CyberSecurity #Tibet #PubLoad #MustangPanda Link: thedailytechfeed.com/chinese-hack...
June 26, 2025 at 3:06 PM
IBM X-Force researchers Golo Mühr & Joshua Chung discovered China-aligned threat actor Hive0154 spreading Pubload malware, featuring lure documents and filenames targeting the Tibetan community. www.ibm.com/think/x-forc...
June 25, 2025 at 9:21 AM

🕵️‍♂️ Chinese hackers, Mustang Panda, targeted Myanmar's Ministry of Defence and Foreign Affairs using custom #malware like PUBLOAD and TONESHELL. They delivered it through disguised #Microsoft updates and booby-trapped files.
thehackernews.com/2024/01/chin...
#cybersecurity
China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz
Chinese hackers Mustang Panda caught red-handed targeting Myanmar's Ministry of Defence and Foreign Affairs
thehackernews.com
January 30, 2024 at 7:53 PM
TibCERT rapidly circulate a cyber safety advisory based on X-Force researchers Golo Mühr & Joshua Chung's recent discovery of PRC-aligned threat actor Hive0154 ( #MustangPanda) using Pubload malware, featuring lure documents and filenames targeting the #Tibetan community www.ibm.com/think/x-forc...
June 28, 2025 at 12:55 AM
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

Ravie LakshmananMar 30, 2026Threat Intelligence / Network Intrusion Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described…
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Ravie LakshmananMar 30, 2026Threat Intelligence / Network Intrusion Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation." The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL RAT, PoshRAT, TrackBak Stealer, RawCookie, Hypnosis Loader, and FluffyGh0st.
nexttech-news.com
March 30, 2026 at 2:27 PM
Mustang Panda利用PUBLOAD与Pubshell恶意软件发动针对西藏社区的精准网络攻击

https://qian.cx/posts/F19E216A-481F-47BC-A88A-409F9290566B
September 25, 2025 at 10:46 PM
PUBLOAD и Pubshell: Новые инструменты Mustang Panda в целевых атаках на тибетское сообщество

https://kripta.biz/posts/E344753C-9471-4791-8312-7FAF47526376
September 25, 2025 at 10:46 PM
Unit 42 revealed a complex Chinese cyberespionage campaign targeting a Southeast Asian government using three clusters deploying USBFect, PUBLOAD, and FluffyGh0st for stealthy data theft. #ChinaHack #SoutheastAsia #USBMalware
The Triple-Headed Dragon: Inside the Three-Cluster Chinese Cyberespionage Campaign Targeting SE Asia
Unit 42 exposed a large, persistent cyberespionage campaign targeting a high-value Southeast Asian government organization, operated by three concurrent activity clusters linked to China-aligned threat actors. The clusters used USBFect/PUBLOAD via infected removable media, a multi-payload toolkit including EggStremeFuel and Masol/Gorem/TrackBak, and the Hypnosis loader delivering FluffyGh0st to maintain stealthy, long-term...
www.hendryadrian.com
April 3, 2026 at 4:20 AM
Unit 42 uncovered coordinated cyberespionage targeting a Southeast Asian government using USBFect/HIUPAN and PUBLOAD backdoor. Clusters CL-STA-1048/1049 deployed RATs linked to China-aligned groups. #SoutheastAsia #PUBLOAD #EggStremeFuel
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government
Unit 42 investigators uncovered coordinated cyberespionage campaigns from June–August 2025 targeting a Southeast Asian government organization, involving USB-propagated USBFect/HIUPAN that deployed the PUBLOAD backdoor and two additional clusters (CL-STA-1048 and CL-STA-1049) using multiple loaders and RATs. The campaigns deployed tools including EggStremeFuel, Masol, EggStreme loader (Gorem RAT), TrackBak stealer, and the...
www.hendryadrian.com
March 27, 2026 at 9:20 AM
China-linked hackers #MuetangPanda just targeted Tibetans with fake documents tied to the Dalai Lama & WPCT.

A new malware chain: Claimloader → PUBLOAD → Pubshell (reverse shell access).

The twist? It spreads via Google Drive links & even USB worms.thehackernews.com/20...
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
Mustang Panda malware targets Tibet and Taiwan, using spear-phishing emails and PUBLOAD for cyber espionage.
thehackernews.com
June 29, 2025 at 7:25 AM
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
thehackernews.com
June 27, 2025 at 2:36 PM
Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments
Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments
Mustang Panda's refined malware tools, including PUBLOAD and PlugX, target APAC governments, escalating cyber espionage.
thehackernews.com
September 10, 2024 at 10:22 AM
Mustang Panda is targeting the Tibetan community with PUBLOAD and Pubshell malware campaigns and may be migrating to US targets.

Mustang Panda (also tracked as Hive0154, Earth Preta, or Camaro Dragon), a China-aligned advanced persistent threat (APT) group, has deployed PUBLOAD and Pubshell…
Mustang Panda is targeting the Tibetan community with PUBLOAD and Pubshell malware campaigns and may be migrating to US targets.
Mustang Panda (also tracked as Hive0154, Earth Preta, or Camaro Dragon), a China-aligned advanced persistent threat (APT) group, has deployed PUBLOAD and Pubshell malware in a targeted cyber espionage campaign against the Tibetan community. This operation leverages Tibet-themed lures to deliver multi-stage malware for persistent access and data exfiltration.
www.spartechsoftware.com
June 27, 2025 at 2:47 PM
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

Ravie LakshmananMar 30, 2026Threat Intelligence / Network Intrusion Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described…
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Ravie LakshmananMar 30, 2026Threat Intelligence / Network Intrusion Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation." The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL RAT, PoshRAT, TrackBak Stealer, RawCookie, Hypnosis Loader, and FluffyGh0st.
nexttech-news.com
March 30, 2026 at 2:27 PM
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
A China-linked threat actor known as Mustang Panda has been attributed to a new cyber espionage campaign directed against the Tibetan community.
Link Preview
Visit the link for more information
thehackernews.com
June 27, 2025 at 1:55 PM
Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor
Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor
www.ibm.com
June 28, 2025 at 9:24 PM
China-Linked groups target Southeast Asian government with advanced malware in 2025

China-linked groups hit a Southeast Asian government in 2025, deploying multiple malware families in a sophisticated cyber campaign. In 2025, three China-linked threat clusters targeted a Southeas…
#hackernews #news
China-Linked groups target Southeast Asian government with advanced malware in 2025
China-linked groups hit a Southeast Asian government in 2025, deploying multiple malware families in a sophisticated cyber campaign. In 2025, three China-linked threat clusters targeted a Southeast Asian government in a complex, well-funded cyber operation. Threat actors deployed numerous malware types, including HIUPAN, PUBLOAD, EggStremeFuel/Loader, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st, showing […]
securityaffairs.com
March 31, 2026 at 2:58 PM
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation."
The cam…
#hackernews #news
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation." The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL
thehackernews.com
March 31, 2026 at 12:35 AM
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack

A China-linked threat actor known as Mustang Panda has been attributed to a new cyber espionage campaign directed against the Tibetan community.
The spear-phishing attacks leveraged topics related to Tibe…

#hackernews #news
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
A China-linked threat actor known as Mustang Panda has been attributed to a new cyber espionage campaign directed against the Tibetan community. The spear-phishing attacks leveraged topics related to Tibet, such as the 9th World Parliamentarians' Convention on Tibet (WPCT), China's education policy in the Tibet Autonomous Region (TAR), and a recently published book by the 14th Dalai Lama,
thehackernews.com
June 28, 2025 at 6:02 PM
Pandas with a purpose. [Research Saturday]

This week, we are joined by Deepen Desai, Zscaler's Chief Security Officer and EVP of Cyber and AI Engineering, taking a dive deep into Mustang Panda’s latest campaign. Zscaler ThreatLabz uncovered new tools used by Mustang Panda, inclu…

#hackernews #news
Pandas with a purpose. [Research Saturday]
This week, we are joined by Deepen Desai, Zscaler's Chief Security Officer and EVP of Cyber and AI Engineering, taking a dive deep into Mustang Panda’s latest campaign. Zscaler ThreatLabz uncovered new tools used by Mustang Panda, including the backdoors TONEINS, TONESHELL, PUBLOAD, and the proxy tool StarLoader, all delivered via phishing. They also discovered two custom keyloggers, PAKLOG and CorKLOG, and an EDR evasion tool, SplatCloak, highlighting the group's focus on surveillance, persistence, and stealth in cyberespionage operations.4o. The research can be found here: Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1 Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2
thecyberwire.com
May 25, 2025 at 5:06 PM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Friday, June 27, 2025
PUBLOAD and Pubshell Malware Used in Mustang Panda's Tibet-Specific Attack
Mustang Panda malware targets Tibet and Taiwan, using spear-phishing emails and PUBLOAD for cyber espionage.
thehackernews.com
June 27, 2025 at 8:20 PM