Hide Navigation Hide TOC hcdLoader (12bb8f4f-af29-49a0-8c2c-d28468f28fd8) hcdLoader is a remote access tool (RAT) that has been used by APT18. Cluster A Galaxy A Cluster B Galaxy B Level hcdLoader - S0071 (9e2bba94-950b-4fcf-8070-cb3f816c5f4e) Malware hcdLoader (12bb8f4f-af29-49a0-8c2c-d28468f28fd8) RAT 1 hcdLoader - S0071 (9e2bba94-950b-4fcf-8070-cb3f816c5f4e) Malware Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern 2 hcdLoader - S0071 (9e2bba94-950b-4fcf-8070-cb3f816c5f4e) Malware Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern 2 Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) Attack Pattern Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern 3 Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) Attack Pattern 3