Investigations by Trend Micro and Orange Cyberdefense found that intrusions involving the ShadowPad and PlugX backdoors culminated in deployment of NailaoLocker ransomware against organizations in Europe. Trend Micro reported that attackers used WmiExec from the Impacket toolkit for remote access and likely copied Active Directory database contents into files named aaaa.dit for offline password cracking, indicating an effort to expand privileges and move laterally before ransomware execution.
Researchers linked the activity to ShadowPad command-and-control infrastructure including updata.dsqurey[.]com, then pivoted to additional related domains and IP addresses. Attribution remains unresolved: Trend Micro said there are only weak ties to the TeleBoyi threat actor, based on overlaps with a historical PlugX sample, shared dsqurey[.]com infrastructure, and similarities in string decryption routines and PE icons, but the report said the timing of domain re-registration and long gaps in resolution history prevent a confident actor link.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
In January 2024, the IP address 108.61.163[.]91 resolved to dscriy.chtq[.]net, which investigators linked to the threat actor in this case. This later resolution was compared with the 2022 Operation Harvest overlap.
After expiring in late March 2022, dsqurey[.]com was registered again on 2022-06-23. Investigators said they could not determine whether the same actor re-registered it, weakening attribution confidence.
In May 2022, the IP address 108.61.163[.]91 resolved to sery.brushupdata[.]com, a domain listed in Operation Harvest. Investigators later used this overlap as a weak link to TeleBoyi-associated infrastructure.
The domain dsqurey[.]com, later linked to PlugX and ShadowPad infrastructure discussed in the investigation, was initially registered. This registration became part of later attribution analysis.
The report notes that PlugX has existed since at least 2008 and has been used in multiple targeted attacks, usually by Chinese threat actors. It is described as the predecessor to ShadowPad.
The report concluded there was not enough evidence to confidently attribute the ShadowPad activity to a known threat actor. It identified two low-confidence links to TeleBoyi based on a historical PlugX sample, shared dsqurey[.]com infrastructure, and similarities in string decryption and PE icons.
By pivoting from the observed infrastructure, investigators identified additional related IP addresses and at least three more linked domain names, with some tied to other ShadowPad samples. These overlaps, along with matching TTPs from another blog post, reinforced the view that the infrastructure was connected to the same actor.
Investigators described an intrusion in which ShadowPad malware was used, including WmiExec-based remote access and likely dumping of Active Directory data into files named aaaa.dit for offline password cracking. The activity ultimately led to ransomware deployment, and the command-and-control domain updata.dsqurey[.]com was observed in both incident response cases.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcetrendmicro.com
Open sourceorangecyberdefense.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.