Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
1 malware family

shadowpad

Also known asShadowPad

ShadowPad is malware/tooling referenced in the provided content in connection with advanced intrusion activity and a later campaign exploiting a Microsoft WSUS remote code execution vulnerability (CVE-2025-59287). The content associates related DLL sideloading activity with ShadowPad, also referred to in one cited context as “NetSarang.” Reported activity targeted government organizations in Asia, and the report notes that DLL sideloading has historically been a favored technique of China-based APT groups, but the content does not directly and conclusively attribute ShadowPad itself to a specific state. In the detailed intrusion reporting, activity linked elsewhere to ShadowPad/NetSarang involved repeated DLL sideloading using legitimate signed applications including Cisco Webex components, VLC Media Player, Razer Chromium Render Process, Microsoft Symbol Server Builder, and a Bitdefender Crash Handler executable. The cases described shared infrastructure, loader shellcode, and code-flow obfuscation. Observed behaviors included encrypted plugin loading, reverse shell execution, process hollowing, UAC bypass via CMSTPLUA and via fodhelper.exe/ComputerDefaults.exe, service creation, autorun persistence, and anti-security actions such as attempting to stop Kaspersky avp.exe. One case involved a USB worm that propagated via removable drives. VirusTotal hunting linked 2022 activity to related 2021 samples, including a sideloading chain previously reported in association with ShadowPad or NetSarang. Separately, the content states that ShadowPad malware was used in attacks exploiting WSUS RCE vulnerability CVE-2025-59287 and that the campaign used the vulnerability to establish persistence on compromised systems.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.