Researchers detailed how ShadowPad, a modular remote access trojan active since at least 2017, has been used by the Chinese threat group BRONZE ATLAS—also tracked as APT41, Axiom, Winnti, and Wicked Panda—and later adopted by multiple other Chinese espionage clusters. Secureworks and Sophos said the malware is commonly deployed through DLL sideloading and DLL search order hijacking with legitimate executables, using two-file and three-file execution chains, in-memory payload decryption, persistence through Windows services and registry keys, and process injection into child processes. The reporting links separate ShadowPad activity clusters to actors aligned with China’s Ministry of State Security and to PLA-affiliated groups whose targeting maps to Northern, Southern, and Western Theater Command regions.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Infosecurity Magazine reported that threat actors associated with the ShadowPad malware targeted government entities in Asia. This added a new campaign development showing continued operational use of ShadowPad against regional government victims beyond the earlier supply-chain cases.
PolySwarm published a profile of Wicked Panda summarizing prior research that tied the group and related Chinese clusters to ShadowPad operations and PLA theater-command-aligned activity. The article consolidated attribution and tradecraft details rather than disclosing a new incident.
Secureworks CTU published an analysis describing ShadowPad's DLL sideloading execution chains, in-memory decryption, persistence mechanisms, process injection, and indicators of compromise. The report also assessed links between ShadowPad activity clusters and MSS- and PLA-affiliated Chinese groups.
Positive Technologies reported that it discovered the previously unknown xDll backdoor in March 2020 and, via an exposed C2 server, uncovered ShadowPad, a Python backdoor, and attacker tools tied to Winnti/APT41 infrastructure active since early 2019. The researchers observed more than 50 infected systems and over 150 related IPs across victims in the United States, Netherlands, Russia, China, and Germany, warning the activity could support another supply-chain attack.
The references note that in 2020 several affiliates associated with Wicked Panda/APT41 were charged for computer intrusion campaigns affecting more than 100 victims worldwide. The legal action is cited as part of the broader public attribution history around actors tied to ShadowPad use.
Research cited in the references states that ShadowPad was involved in major 2017 supply-chain attacks affecting CCleaner and ASUS Live Update in addition to NetSarang. These incidents broadened understanding of the malware's role in high-impact software supply-chain compromises.
Kaspersky disclosed that attackers had embedded the ShadowPad backdoor in NetSarang software used by large companies worldwide, marking one of the earliest major public incidents involving the malware. The disclosure established ShadowPad as a significant supply-chain threat.
Secureworks research says the Chinese state-sponsored BRONZE ATLAS group has used the modular ShadowPad remote access trojan since at least 2017. This marks the earliest stated operational use of ShadowPad by that cluster in the provided references.
According to Secureworks, ShadowPad use expanded from around 2019 onward to multiple Chinese threat groups operating globally. The report links separate activity clusters to MSS-affiliated and PLA-affiliated actors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcesophos.com
Open sourcesophos.com
Open sourcesecureworks.com
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcepwc.co.uk
Open sourceweb.archive.org
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.