ShadowLink is a post-compromise backdoor/persistence tool used to provide covert remote access. High-confidence reporting in the provided content describes two observed forms of ShadowLink. In Microsoft reporting on the Seashell Blizzard (Sandworm/APT44) BadPilot campaign, ShadowLink is a Tor-based persistence capability that installs and configures a Tor hidden service on a compromised host, assigns the system a .onion address, and commonly forwards inbound connections to RDP (port 3389) to enable remote access. It may be made persistent by masquerading as an MS Defender application. Microsoft links this usage to a Russian state actor associated with GRU Unit 74455, with targeting across sectors including energy, oil and gas, telecommunications, shipping, arms manufacturing, and government, and with activity expanding to the United States, United Kingdom, Canada, and Australia.
Separately, the content describes a custom command-and-control beacon also named ShadowLink that was found on compromised TP-Link and ASUS routers and in the backdoored Xygeni GitHub Action used in a March 2026 supply-chain attack. Investigators reported that the ShadowLink protocol was identical across the router malware and the Xygeni payload, including shared registration paths, command polling logic, and the same authentication secret, indicating the same operator. On TP-Link devices, ShadowLink was deployed alongside microsocks after exploitation of CVE-2024-21833, registered with C2, polled for commands, executed them via eval, and exfiltrated base64-encoded results. The TP-Link stager downloaded architecture-specific payloads, established a SOCKS5 proxy, and deployed the ShadowLink beacon; persistence was achieved via cron, /etc/rc.local, and NVRAM rc_startup changes. An ASUS-targeting variant fingerprinted device model, firmware version, and architecture via ASUSWRT nvram and sent that data to C2. Across observed variants, ShadowLink used POST /b/in for registration and the HTTP header X-B: sL5x#9kR!vQ2$mN7 for authentication. In the Xygeni compromise, a malicious GitHub Actions step concealed a ShadowLink beacon in a background subshell that registered with C2, polled for commands for 180 seconds, executed them via eval, and exfiltrated results using zlib compression and base64 encoding via security-verify.91.214.78.178.nip[.]io.
Overall, the provided content supports describing ShadowLink as a covert remote-access/backdoor capability used for persistence and command-and-control, observed both as a Tor hidden-service access mechanism and as a custom HTTP beacon in router and CI/CD supply-chain compromises.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These routers were also running a custom command-and-control beacon that was named ShadowLink. When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply-chain attack. | The primary payload, tplink_stager.sh, was designed for post-exploitation of CVE-2024-21833, an OS command injection vulnerability (CVSS 8.8) affecting TP-Link Archer and Deco series routers.
Since early 2024, the subgroup has expanded its range of access to include targets in the United States and United Kingdom by exploiting vulnerabilities primarily in... Fortinet FortiClient EMS security software (CVE-2023-48788). Both CVE-2024-1709 and CVE-2023-48788 provided the ability to launch arbitrary commands on a vulnerable server. | ...in addition to a unique persistence and assured C2 method known to Microsoft Threat Intelligence as ShadowLink.
Since early 2024, the subgroup has expanded its range of access to include targets in the United States and United Kingdom by exploiting vulnerabilities primarily in ConnectWise ScreenConnect (CVE-2024-1709) IT remote management and monitoring software... This was first observed when the subgroup exploited vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1709) and Fortinet FortiClient EMS (CVE-2023-48788). | ...in addition to a unique persistence and assured C2 method known to Microsoft Threat Intelligence as ShadowLink.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These routers were also running a custom command-and-control beacon that was named ShadowLink. When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply-chain attack.
...in addition to a unique persistence and assured C2 method known to Microsoft Threat Intelligence as ShadowLink.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations.
Persistence on the TP-Link devices was achieved through three mechanisms... RC scripts -> modification of /etc/rc.local.
Persistence on the TP-Link devices was achieved through three mechanisms: Cron -> /var/spool/cron/crontabs/root or /etc/crontabs (every 5 minutes).
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations.
Persistence on the TP-Link devices was achieved through three mechanisms... RC scripts -> modification of /etc/rc.local.
Adversaries may get ShadowLink to persist on a system by masquerading it as an MS Defender application.
Each malicious commit contained a GitHub Actions step named “Report Scanner Telemetry” which may have blended in with legitimate CI/CD pipeline steps.
tplink_stager.sh self-deletes original and cleans wget/curl temp files.
All three scripts implement the same core beaconing protocol: registration via POST /b/in with a custom HTTP authentication header... ShadowLink C2 over HTTP; JSON payloads to /b/in, /b/q, /b/r.
Adversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool ShadowLink to facilitate the installation and configuration of the Tor hidden service.
ShadowLink facilitates persistent remote access by configuring a compromised system to be registered as a Tor hidden service... Systems compromised with ShadowLink receive a unique .onion address, making them remotely accessible via the Tor network.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom command-and-control beacon/backdoor used across compromised TP-Link routers, ASUS routers, and the Xygeni GitHub Action supply-chain attack. It registers with a C2 via POST /b/in, polls for commands via GET /b/q, executes commands via eval, and exfiltrates results via POST /b/r using base64 encoding, with one variant using zlib plus base64. On TP-Link devices it was paired with microsocks to build residential proxy infrastructure.
Custom persistence and remote access capability that registers compromised systems as Tor hidden services to provide covert remote access and evade traditional C2 detection.
ShadowLink is a tool used to install and configure a Tor hidden service on a compromised system, enabling persistent remote access over the Tor network and forwarding inbound connections such as RDP.
ShadowLink is a tool used to install and configure a Tor hidden service on a compromised host, establish a .onion address, forward inbound connections such as RDP, and maintain covert remote access and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.