Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. HUI Loader

HUI Loader

HUI Loader is a custom DLL loader that has been used since at least 2015 by China-based threat groups includingCinnamon Tempest andmenuPass to deploy malware on compromised hosts.HUI Loader has been observed in campaigns loadingSodaMaster,PlugX,Cobalt Strike,Komplex, and several strains of ransomware.[1]

ID: S1097
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 22 December 2023
Last Modified: 02 January 2024
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1140Deobfuscate/Decode Files or Information

HUI Loader can decrypt and load files containing malicious payloads.[1]

EnterpriseT1574.001Hijack Execution Flow:DLL

HUI Loader can be deployed to targeted systems via legitimate programs that are vulnerable to DLL search order hijacking.[1]

EnterpriseT1562.006Impair Defenses:Indicator Blocking

HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions.[1]

Groups That Use This Software

References

×

[8]ページ先頭

©2009-2026 Movatter.jp