Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

HeaconLoad

HeaconLoad is a Golang downloader observed in a large-scale GitHub-based malware distribution campaign documented by Trend Micro. In that operation, attackers used more than 100 public GitHub repositories, SEO-stuffed README files, and fake download pages to distribute ZIP archives masquerading as legitimate software tools, utilities, and game cheats. HeaconLoad was delivered either as an additional payload alongside the BoryptGrab information stealer and other malware, or directly within some delivered bundles.

Trend Micro reported that HeaconLoad downloads and executes additional payloads, maintains persistence via registry entries and scheduled tasks, sends system information to a command-and-control server, and retrieves additional bundles when available. The broader infection chains in the campaign included DLL sideloading, VBS/PowerShell downloaders, and .NET loaders. The same campaign also delivered BoryptGrab, Vidar variants, and a PyInstaller backdoor named TunnesshClient. Supporting evidence cited by Trend Micro, including Russian-language comments and infrastructure artifacts, suggests the operators may be of Russian origin.

High-confidence behavioral details directly mentioned in the content for HeaconLoad are: it is written in Go, functions as a downloader, downloads and runs additional payloads, persists through registry entries and scheduled tasks, and transmits host system information to its C2. The campaign primarily targeted Windows users seeking software tools or game cheats via GitHub-hosted lures and fake download pages.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1053.005Scheduled TaskEvidence1

...sets scheduled tasks to keep the malware running.

Persistence

2 techniques
T1053.005Scheduled TaskEvidence1

...sets scheduled tasks to keep the malware running.

T1547.001Registry Run Keys / Startup FolderEvidence1

HeaconLoad maintains persistence with registry entries and scheduled tasks...

Privilege Escalation

3 techniques
T1053.005Scheduled TaskEvidence1

...sets scheduled tasks to keep the malware running.

T1055Process InjectionEvidence1

...obfuscation techniques such as XOR-encrypted strings, dynamic API resolution, and code injection.

T1547.001Registry Run Keys / Startup FolderEvidence1

HeaconLoad maintains persistence with registry entries and scheduled tasks...

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1

Several payloads rely on obfuscation techniques such as XOR-encrypted strings, dynamic API resolution, and code injection.

T1055Process InjectionEvidence1

...obfuscation techniques such as XOR-encrypted strings, dynamic API resolution, and code injection.

Discovery

1 technique
T1082System Information DiscoveryEvidence1

...stealing browser data, crypto wallets, system information... gathers system details... records installed applications.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

HeaconLoad... sends system information to a command-and-control server, and downloads additional bundles when available.

T1105Ingress Tool TransferEvidence1

The launcher downloads the BoryptGrab information stealer and may also retrieve other payloads, including Vidar variants... and a Golang downloader named HeaconLoad.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.