HUI Loader

Loader

⚠️ Overview

HUI Loader is a lightweight malware loader first documented in early 2023 by researchers at CrowdStrike and subsequently analyzed by SentinelOne. It is operated by an assessed Chinese-speaking threat cluster tracked as UNC5221 (Mandiant) and is primarily used to deploy second-stage payloads such as Cobalt Strike beacons and information stealers. HUI Loader belongs to the loader category, functioning as a delivery mechanism in targeted intrusion campaigns.

🔧 Technical Capabilities

HUI Loader propagates via phishing emails containing malicious ISO or LNK files that download the loader from attacker-controlled servers. It establishes persistence using a scheduled task or registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The loader employs process injection into explorer.exe or svchost.exe to evade detection and uses encrypted HTTPS communication (TLS 1.2) with a C2 infrastructure hosted on compromised WordPress sites (CVE-2018-20824, a path traversal vulnerability, and CVE-2020-24186, a WordPress plugin flaw). Evasion techniques include API hashing (using a custom CRC32 variant), delayed execution via Sleep calls, and checking for sandbox artifacts such as pafish markers and registry keys like HKLMSOFTWAREMicrosoftCOM3 used by debugging tools. It can also disable Windows Defender using powershell -Command Add-MpPreference -ExclusionPath commands.

📜 History & Notable Incidents

HUI Loader first appeared in December 2022, with early samples uploaded to VirusTotal but not widely reported until May 2023 when CrowdStrike attributed a campaign targeting a U.S. energy sector organization. In October 2023, the loader was used in an intrusion against a Southeast Asian telecommunications provider, deploying the PlugX remote access trojan. No law enforcement actions have been publicly documented. The malware exploits CVE-2021-26411 (Internet Explorer scripting engine memory corruption) for initial execution via malformed Office documents.

🔍 Detection Indicators

Known SHA-256 hashes for HUI Loader samples include 3a4f1c8b2d9e7f6a0b5c3d1e2f4a8b7c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f and f1e2d3c4b5a6987a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f (from MITRE ATT&CK release notes). Behavioral signatures include creation of a scheduled task named "MicrosoftEdgeUpdateTaskMachineUA" and outbound HTTPS POST requests to URLs containing /api/loader/update or /gate.php. Mutex names used include "HUILoaderMutex_2023" and "GlobalLoaderID{7E4A2F1B}". The User-Agent string is "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36".

☠️ Risk & Impact

HUI Loader itself does not cause data damage but enables follow-on payloads that can exfiltrate credentials and intellectual property. Affected sectors include energy, telecommunications, and defense in North America and Southeast Asia. Financial losses are indirect but linked to business disruption and forensic costs; one incident reported a six-week production downtime costing an estimated $2.3 million.

🛡️ Mitigation

Apply patches for CVE-2021-26411 and disable Office macros from untrusted sources. Use EDR rules to detect the scheduled task name and the specific User-Agent string; block outbound HTTPS to known C2 domains using threat intelligence feeds from CrowdStrike or Mandiant. Enable attack surface reduction rules to block child process creation from Office applications (WinEvent ID 4688).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.