Researchers have tied ShadowPad, a modular malware platform sold privately rather than shared openly, to multiple high-profile espionage operations and supply-chain compromises. Analysis indicates the backdoor emerged as a successor to PlugX and has been used by several China-linked activity clusters, including subgroups associated with APT41 as well as actors previously linked to Axiom. Investigators say ShadowPad’s architecture allows its developer to restrict plugin access per customer, helping multiple espionage teams reuse the same malware while complicating attribution and lowering development costs for operators.
ShadowPad has surfaced in several notable intrusions, including the CCleaner compromise, where a trojanized installer reached about 2.27 million users but a second-stage payload was delivered to only 40 selected systems; investigators also found ShadowPad on Piriform machines with decrypted logs showing keylogging activity. It was also linked to Operation ShadowHammer, in which attackers trojanized ASUS Live Update binaries that retained valid ASUSTeK signatures and selectively activated only on devices whose network-adapter MAC addresses matched hardcoded target lists before contacting asushotfix[.]com for a second stage. Reporting also connects related activity to compromises involving NetSarang, corporate networks, and Asian gaming-sector targets, reinforcing ShadowPad’s role as a recurring tool in selective, supply-chain-enabled Chinese espionage.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs reported that since 2017 it had identified at least five ShadowPad activity clusters, including APT41, Tick and Tonto Team, Operation Redbonus, Operation Redkanku, and Fishmonger, and argued the malware is privately sold rather than openly shared.
Kaspersky released a detailed report on Operation ShadowHammer, describing trojanized ASUS Live Update binaries, compromised signing material, over 600 target MAC addresses, and links to ShadowPad-related tooling.
Norfolk Infosec states Kaspersky published details on March 25 about the ASUS supply-chain compromise, including that malicious code was pushed through ASUS Live Update.
Kaspersky researchers discovered the trojanized ASUS Live Updater at the end of January 2019, uncovering a supply-chain attack that selectively targeted victims by MAC address.
Kaspersky assessed that the attackers changed payload start routines between late July and September 2018 during the ASUS supply-chain operation, likely to improve evasion.
Kaspersky noted Reddit discussions in June 2018 and September 2018 about suspicious ASUS Live Update behavior, suggesting malicious delivery may have started as early as June 2018.
Kaspersky identified related ASUS compromise samples compiled between June and July 2018 that contacted asushotfix[.]com, indicating the ShadowHammer activity was underway by mid-2018.
The tampering of Piriform's CCleaner installer was disclosed on September 18, 2017; about 2.27 million users downloaded the trojanized installer, while only 40 systems received the second-stage payload.
Avast acquired Piriform on July 18, 2017, shortly after the period during which the CCleaner build environment had been compromised.
Investigators determined ShadowPad was installed on four Piriform systems on April 12, 2017, and keylogger logs showed keystroke collection began the same day.
Investigators found a preliminary version of the CCleaner attack's stage-two binary installed on Piriform computers on March 12, 2017, indicating attacker presence in the environment before public disclosure.
Avast said malware was introduced into Piriform's build server sometime between March 11 and July 4, 2017, enabling the later CCleaner supply-chain attack.
SentinelLabs reported that ShadowPad controller version 1.0 dates to 2015, marking the malware platform's emergence as a successor to PlugX.
Avast's updated CCleaner investigation disclosed that ShadowPad had been found on four Piriform computers, with decrypted logs showing keylogging activity and suggesting a custom build tailored for Piriform.
A follow-up analysis described the first-stage ASUS malware as a triage tool that hashed MAC addresses, compared them to a hardcoded target list, and contacted asushotfix[.]com only for selected victims.
ESET published research stating that the gaming industry was still in scope for attackers in Asia, contributing reporting on the broader threat landscape tied to the story.
Kaspersky published research on ShadowPad in corporate networks, documenting the malware's presence and use in intrusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcesecurelist.com
Open sourcenorfolkinfosec.com
Open sourcewelivesecurity.com
Open sourcesecurelist.com
Open sourceblog.avast.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.