Threat actors have exploited a critical deserialization vulnerability in Microsoft Windows Server Update Services (WSUS), identified as CVE-2025-59287, to gain remote code execution with system privileges and deploy the ShadowPad backdoor. The attackers targeted publicly exposed WSUS-enabled Windows Servers, using the PowerCat utility to obtain a system shell and then leveraging legitimate Windows tools such as curl.exe and certutil.exe to download and install ShadowPad from an external server. ShadowPad, a modular backdoor associated with Chinese state-sponsored groups, is loaded via DLL side-loading techniques, specifically using a legitimate binary to execute a malicious DLL payload in memory.
The vulnerability, which was patched by Microsoft in October, allows remote, unauthenticated attackers to trigger unsafe deserialization of AuthorizationCookie objects, leading to full system compromise. Security researchers from AhnLab and others have documented the attack chain, noting that the flaw has been added to CISA's Known Exploited Vulnerabilities catalog and that a public proof-of-concept exploit is available. The incident highlights the ongoing risk posed by unpatched WSUS servers and the sophisticated methods used by threat actors to maintain persistence and evade detection once ShadowPad is installed.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Security reporting linked the ShadowPad deployment campaign to Chinese state-aligned threat actors, with references to groups such as APT41, APT10, and PLA-affiliated clusters. The activity was described as targeting sectors including manufacturing, telecom, and energy.
Following evidence of active exploitation, CISA added CVE-2025-59287 to its Known Exploited Vulnerabilities catalog and pushed for urgent remediation. Subsequent reporting also described mandated or strongly urged patching and access restrictions for affected organizations.
AhnLab Security Intelligence Center reported observing the WSUS exploitation chain in the wild, detailing the use of legitimate Windows binaries and the delivery of ShadowPad. Its findings provided technical confirmation of ongoing attacks against publicly exposed WSUS instances.
Attackers actively exploited CVE-2025-59287 to gain SYSTEM-level access on WSUS servers, using PowerCat for shell access and certutil and curl to download ShadowPad. The malware was deployed via DLL sideloading and used persistence and anti-detection techniques, with some intrusions also involving reconnaissance and tools such as Velociraptor.
After proof-of-concept exploit code for CVE-2025-59287 was publicly released, attackers quickly began weaponizing the flaw against exposed WSUS servers. Reports describe this publication as the catalyst for active exploitation.
Microsoft released an out-of-band patch for CVE-2025-59287, a critical unsafe deserialization flaw in the WSUS GetCookie() endpoint that can allow unauthenticated remote code execution as SYSTEM. Multiple reports place the patch release in October 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
foresiet.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.