Researchers and incident responders have tied ShadowPad, a privately sold modular backdoor associated with multiple PRC-linked espionage operations, to both major supply-chain compromises and ongoing targeted intrusions. ShadowPad has appeared in high-profile cases including CCleaner, NetSarang, and ASUS ShadowHammer, while a separate campaign used a trojanized installer for Pakistan’s government E-Office application to sideload a malicious mscoree.dll loader and deploy an encrypted ShadowPad payload. Trend Micro observed victims in Pakistan spanning a government entity, a public sector bank, and a telecommunications provider, with follow-on activity including credential theft via Mimikatz and data exfiltration over PowerShell BITS. ShadowPad was also among the malware families deployed after mass exploitation of Microsoft Exchange zero-days, underscoring its role as a reusable espionage platform across both opportunistic and highly selective operations.
Defenders have responded by reverse engineering ShadowPad’s custom TCP, HTTP(S), and UDP command-and-control protocols and using protocol emulation to scan the Internet for live servers that would evade reputation-based detection. VMware and Virus Bulletin research identified dozens of active ShadowPad C2 nodes—roughly 72 to 83 servers across overlapping study periods—and found that some accepted multiple protocols on the same port and overlapped with infrastructure used by Spyder and ReverseWindow. One previously identified ShadowPad C2 IP later surfaced in a real incident response case, showing that proactive C2 discovery can expose stealthy intrusions before conventional indicators trigger. Researchers caution that ShadowPad’s commercial, shared-use model complicates attribution, making infrastructure correlation and long-term tracking more reliable than assuming any single actor is responsible.

TTPs, infrastructure, and targeting history in one profile.
27 events from the most recent confirmed update back to the earliest known activity.
SentinelOne published research describing ShadowPad as a privately sold modular platform, linking its use to multiple espionage clusters and major supply-chain incidents including CCleaner, NetSarang, and ASUS.
Researchers found a legitimate installer for E-Office version 2.0.3.0 linked from a Pakistan government website between April and July 2023, enabling comparison with the trojanized MSI.
At Virus Bulletin 2023, Daniel Lunghi presented research on a possible supply-chain attack using a trojanized Pakistani E-Office installer to deliver ShadowPad to at least three victims in 2022.
VMware published research on October 27, 2022 detailing ShadowPad protocol reverse engineering and active C2 discovery using protocol emulation.
A second victim, a Pakistani public sector bank, had ShadowPad detections on 30 September 2022 following E-Office installation.
Trend Micro identified a Pakistani government entity as the first confirmed victim of the backdoored E-Office installer on 28 September 2022.
In June 2022, VMware TAU expanded its ShadowPad scanning campaign to UDP port 443 and HTTP port 80 to broaden infrastructure discovery.
Related ShadowPad samples were detected at a Pakistani telecommunications provider in May 2022, with one sample noted as having been present since mid-February 2022.
The number of active Winnti 4.0 C2 servers dropped sharply in November 2021, which Haruyama suspected was related to the disclosures.
Haruyama disclosed discovered Winnti 4.0 C2 information again in November 2021 during his long-term tracking of the malware's infrastructure.
In October 2021, VMware TAU expanded its ShadowPad scanning campaign to TCP port 443 and UDP port 53 to identify additional active C2 servers.
VMware TAU began protocol-aware scanning for ShadowPad infrastructure in September 2021, initially targeting HTTP on port 443.
Both VMware and Haruyama analyzed three ShadowPad variants collected in August 2021 to reverse engineer protocol differences and build variant-specific scanners.
Microsoft released out-of-band patches for Exchange Server 2013, 2016, and 2019 on March 2, 2021 to address the actively exploited ProxyLogon vulnerabilities.
Orange Tsai discovered and reported the Exchange vulnerabilities CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 to Microsoft on January 5, 2021.
Volexity observed in-the-wild exploitation of the ProxyLogon Exchange vulnerabilities starting January 3, 2021, before Microsoft had been notified.
Haruyama disclosed discovered Winnti 4.0 command-and-control information in February 2020 as part of his tracking of active infrastructure.
Haruyama identified a new Winnti 4.0 Worker component from 2018 that had less than 50% code similarity to Winnti 3.0, marking a notable evolution of the malware family.
SentinelOne reported that a ShadowPad controller version 1.0 dated 2015 was accidentally discovered during private research, supporting analysis of how the platform and plugin management worked.
ShadowPad was described as a modular malware platform privately shared with multiple PRC-linked threat actors beginning in 2015, and later characterized as a successor to PlugX.
Between September 2021 and June 2022, Haruyama identified 72 ShadowPad C2 servers representing 67 unique IP addresses through protocol-aware Internet scanning.
Between December 2019 and May 2022, Haruyama identified 51 Winnti 4.0 C2 servers representing 39 unique IP addresses using protocol emulation and scanning.
Between September 2021 and September 2022, VMware TAU identified 83 ShadowPad C2 servers corresponding to 75 unique IP addresses through protocol emulation and scanning.
ESET reported that multiple APT groups had exploited the Exchange vulnerabilities, with telemetry showing webshells on more than 5,000 unique servers across over 115 countries.
After deduplication, Talos confirmed that 20 unique systems received the specialized second-stage payload, with delivery controlled by domain, IP, and hostname filters.
Between September 12 and September 16, more than 700,000 infected machines reported to the CCleaner command-and-control server, according to Talos' review of the attackers' database.
Version 5.33 of CCleaner was distributed as part of a supply-chain compromise, seeding a large number of infected systems with a first-stage backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceblogs.vmware.com
Open sourcewelivesecurity.com
Open sourceblog.talosintelligence.com
Open sourcevirusbulletin.com
Open sourcevirusbulletin.com
Open sourceptsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.