ShadowPad is a modular Windows backdoor and espionage platform in the PlugX lineage, first observed in the 2017 compromise of NetSarang software. It has subsequently been used in major software supply-chain compromises, including operations involving CCleaner and ASUS software, as well as targeted intrusions against government, telecommunications, industrial, energy, technology, and other strategic-sector organizations. ShadowPad is a privately distributed malware platform with separately available plugins and is widely used across the China-nexus APT ecosystem, including activity associated with APT41/Winnti, Earth Naga (Flax Typhoon), Earth Estries, and BRONZE BUTLER; use of the malware alone is not sufficient for actor attribution. The backdoor supports modular post-compromise operations, including host and environment reconnaissance, collection of usernames, domains, process identifiers, and system time, storage of configuration and a virtual file system in the Windows Registry, process injection, and encrypted payload execution. It is frequently installed through DLL sideloading using legitimate signed executables. Observed campaigns have also deployed it laterally within already compromised Windows environments through SMB-based mechanisms and existing backdoors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ivanti Connect Secure Authentication Bypass [CVE-2023-46805] ... Allows unauthenticated attackers to bypass authentication controls. Commonly exploited in conjunction with CVE-2024-21887, enabling remote command execution and full system compromise. Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
Some of the victim organizations were breached by exploiting the CVE-2021-26855 vulnerability in Microsoft Exchange... The attackers exploited a known vulnerability in MS Exchange, CVE-2021-26855, as the initial attack vector in several victim organizations. | In mid-October 2021 Kaspersky ICS CERT researchers uncovered an active ShadowPad backdoor infection on industrial control systems (ICS) in Pakistan.
CVE-2024-21887: Vulnerability Type: Command Injection ... Allows remote, unauthenticated attackers to execute commands with elevated privileges, potentially leading to full system compromise ... Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
The first vulnerability they used was CVE-2019-9489, a directory traversal vulnerability in Trend Micro Apex One, OfficeScan and Worry-Free Business Security that was patched in April 2019. | ...some more advanced families, such as the ShadowPad malware used in the NetSarang attacks... Earth Akhlut started to make heavy use of ShadowPad in 2019.
The second vulnerability was CVE-2020-8468, patched in March 2020, a content validation escape vulnerability involving Trend Micro Apex One (on premise) and OfficeScan XG, which was exploited to execute code through a malicious update delivered to selected workstations. | ...some more advanced families, such as the ShadowPad malware used in the NetSarang attacks... Earth Akhlut started to make heavy use of ShadowPad in 2019.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Among our finds on the server were utilities for lateral movement... The server had the following utilities: Utilities to check for and exploit vulnerability MS17-010... The hackers tweaked the functionality of the MS17-010 utility by adding the ability to check an entire subnet.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
The malware payloads seen in campaigns investigated by Microsoft Defender vary from remote access trojans (RATs) like VShell and EtherRAT, the SNOWLIGHT memory-based malware downloader that enabled attackers to deploy more payloads to target environments, ShadowPAD, and XMRig cryptominers. | CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components, Next.js, and related frameworks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-3502 is a flaw in TrueConf Client that allows it to download and install updates without verifying them. Attackers who can tamper with the update source can deliver malicious files, leading to arbitrary code execution on the system.
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. | References include https://securelist.com/shadowpad-in-corporate-networks/81432/ and a Kaspersky press release about 'ShadowPad attackers' hiding a backdoor in software used by hundreds of large companies worldwide. The description states the malicious nssock2.dll implements a multi-stage, DNS-based backdoor.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
“We also discovered that APT41 created a tailored loader to inject a proof-of-concept for CVE-2018-0824 directly into memory, utilizing a remote code execution vulnerability to achieve local privilege escalation.” / “During the compromise the threat actor attempts to exploit CVE-2018-0824, with a tool called UnmarshalPwn …”
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...ShadowPad Malware Actively Exploits WSUS Vulnerability... exploiting CVE-2025-59287 for initial access...
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
28 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since March 18, 2025, we have identified that Earth Estries has been deploying the ShadowPad backdoor through multiple vectors within the compromised environment.
Between mid-2020 and March 2021, an adversary breached 10 power sector organizations and two ports in India, based on analysis of ShadowPad command-and-control traffic by Recorded Future. | “Shadowpad: A Masterpiece Of Privately Sold Malware In Chinese Espionage,” SentinelOne
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Deploy malware using compromised user credentials to transfer files via SMB
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
Insikt Group found network intrusions at seven Indian State Load Dispatch Centers (SLDCs) ... The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
Deploy malware using compromised user credentials to transfer files via SMB
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Then the malicious DLL... performs the Process Injection technique: Process Hollowing T1055.012.
Deploy malware using compromised user credentials to transfer files via SMB
Several obfuscation techniques are used by the Winnti Group, such as the use of VMProtect and a custom packer.
mscoree.dll is a commonly used name for loaders of Shadowpad ... The MSI metadata mentioned eOffice ... We compared the legitimate eOffice 2.0.3 installer and our backdoored version
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Then the malicious DLL... performs the Process Injection technique: Process Hollowing T1055.012.
Deploy malware using compromised user credentials to transfer files via SMB
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP. | As the configuration structure shows, the Worker component supports five C2 protocols: TCP, HTTP, HTTPS, TLS and UDP.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The group likely compromised and co-opted internet-facing DVR/IP camera devices for command and control (C2) of ShadowPad malware infections, as well as use of the open source tool FastReverseProxy (FRP).
Both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP.
Deploy malware via Cobalt Strike SMB beacon ... Deploy malware using compromised user credentials to transfer files via SMB
425 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor/framework mentioned as part of the broader ecosystem indirectly linked to the SilkParasite activity, but not described as one of the primary malware families deployed in this campaign.
Backdoor malware referenced as part of the lineage leading to BLOODALCHEMY; widely used by Chinese hacking groups.
Modular backdoor malware used by multiple China-aligned threat actors. In this case it was deployed inside the victim environment and attributed by the report to Earth Naga infrastructure.
Established China-nexus backdoor family identified in the content as part of the malware lineage from which BloodAlchemy derives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.