ShadowPad is a modular backdoor platform and associated activity cluster used in cyberespionage operations by multiple suspected China-nexus threat actors. It has been linked to intrusions attributed with high confidence to Chinese espionage operators, including activity associated with APT41, and broader reporting has connected related operations in the same timeframe to actors linked to APT15 and UNC5174. Rather than representing a single stable intrusion set, the name commonly refers to a malware-centric cluster spanning multiple operators that share tooling, infrastructure patterns, and tradecraft. Operations involving ShadowPad have targeted a wide range of high-value organizations globally, including government entities, media organizations, cybersecurity-related targets, and victims in manufacturing, finance, telecommunications, research, and IT services and logistics. Reported campaigns showed particular interest in cybersecurity vendors and adjacent supply-chain relationships, including reconnaissance and intrusion activity directed at organizations connected to security providers. Observed tradecraft includes exploitation of internet-facing edge devices and enterprise services for initial access, including vulnerabilities affecting network security appliances and server software. Post-compromise activity has included deployment of ShadowPad variants obfuscated with ScatterBrain and ScatterBee, use of additional backdoors such as GOREshell, and operational overlap with infrastructure such as ORB-style relay networks. The operators demonstrated mature defense-evasion practices, including advanced obfuscation, packing, timestomping, and log removal, and used publicly available utilities for network auditing and anti-forensic purposes. The overall pattern is consistent with persistent, well-resourced cyberespionage activity focused on stealthy access, long-term footholds, and intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.