ShadowForce is a threat group active since at least 2013 and known for targeting Korean businesses and government-related agencies, with a particular focus on Microsoft SQL Server environments. The group has been associated with attacks against internet-exposed MS-SQL servers, especially where weak credentials enable compromise through scanning and brute-force activity. After obtaining administrative database access, ShadowForce has used SQL Server features that permit operating-system command execution and post-compromise tooling deployment. A notable aspect of ShadowForce tradecraft is repeated use of CLR-based SqlShell malware deployed as malicious .NET assemblies within SQL Server. The group has used CLRSQL variants that provide broad post-exploitation functionality resembling a web shell, including command execution and host interaction through the database server. Reported ShadowForce-associated builds have included PingCastle-enabled variants for Active Directory reconnaissance and variants incorporating privilege-escalation tooling such as BadPotato and EfsPotato. This indicates an operational workflow that moves from initial access on exposed SQL infrastructure to internal reconnaissance, privilege escalation, and broader post-exploitation. ShadowForce is best characterized as an intrusion-focused actor leveraging exposed database infrastructure as an entry point into Korean organizational networks. Known activity supports capabilities in scanning, brute-force access, initial compromise of MS-SQL servers, reconnaissance, privilege escalation, persistence through SQL-hosted malicious assemblies, and post-exploitation command execution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.