Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

SHADOW-VOID-042

Also known asshadow_void_042

SHADOW-VOID-042 is a temporary intrusion set designation used to track a highly targeted spear-phishing campaign observed in November 2025 that impersonated Trend Micro branding and messaging. The campaign targeted organizations in critical infrastructure-related sectors including defense, energy, and chemicals, and also attempted to infiltrate Trend Micro and its subsidiaries. Lures included urgent, fake security advisories (e.g., a purported vulnerability in Trend Micro Apex One Web Reputation Service) that directed victims to a Trend Micro-mimicking decoy site branded as “TDMSEC.” The infection chain included redirection via a fake Cloudflare browser-check page and delivery of JavaScript-based exploits; one recovered exploit targeted CVE-2018-6065 (Chrome, 2018). Reporting indicates a multi-stage approach with payloads tailored per victim, and researchers assessed that more recent zero-day exploits may have been selectively used against high-value targets, though this was not confirmed. Trend Micro linked the November 2025 activity with high confidence to an October 2025 operation using HR/executive-focused lures (e.g., fake workplace harassment and academic research complaints). The activity shows significant tactical and infrastructure overlap with Void Rabisu (also associated with ROMCOM / Storm-0978), described as Russian-aligned, but a definitive attribution/link was not established due to early disruption and lack of final payload observation (no ROMCOM backdoor was seen in telemetry).

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.002
Spearphishing Link
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.