A SentinelOne LABScon presentation detailed the rise of a prolific cyber espionage actor that evolved over roughly a decade from phishing campaigns and broad malware distribution into a mature, persistent intrusion operation. The actor initially relied on malware such as PlugX and ShadowPad, then shifted toward more tightly controlled tools including Crosswalk, Sidewalk, FunnySwitch, Spider, and the ScatterBee loader as its tradecraft became more selective and sophisticated.
The presentation said the actor has conducted operations across more than 35 countries and targeted multiple sectors, including government and telecommunications. Researchers highlighted ShadowPad as a key component of the ecosystem, noting that the malware has been used by at least 13 distinct threat actors since emerging around 2015, while a new variant found in August 2022 showed continued innovation in execution techniques; the actor also maintained layered infrastructure using relay networks, VPS systems, and tunneling to preserve access and conceal activity.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
A new ShadowPad variant was discovered in August 2022, showing continued innovation in execution techniques. The finding was cited as evidence of the actor's ongoing technical development.
The presentation states that ShadowPad emerged around 2015 and became an important malware platform in the actor's evolution. It was later used by at least 13 distinct threat actors.
At LABScon, Kris McConkey presented research tracing the actor's evolution over roughly a decade from phishing and broad malware distribution to more sophisticated tooling and entrenched operations. The talk highlighted the actor's global reach across more than 35 countries and multiple sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.