Proofpoint reported that the WhiteShadow downloader was being distributed through malicious Microsoft Word and Excel attachments in email campaigns, using Visual Basic macros to contact attacker-controlled Microsoft SQL Server instances over SQLOLEDB. The macros retrieved ASCII-encoded payload data from the databases, decoded it into a ZIP archive, extracted a Windows executable, and launched the next-stage malware, showing a staged delivery chain that relied on MSSQL rather than more typical web-based retrieval methods.
The campaigns were described as low- to medium-volume and were used to deliver multiple commodity malware families, including Crimson, NanoCore, njRAT, Agent Tesla, AZORult, Formbook, Orion Logger, Remcos, and Netwire. Proofpoint assessed that WhiteShadow appeared to operate as a malware delivery service built around related MSSQL infrastructure, with only basic but evolving macro obfuscation, and said defenders could use outbound TCP port 1433 traffic as a key detection and control point.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
On September 26, 2019, Proofpoint published research describing WhiteShadow's use of Microsoft SQL Server databases to retrieve ASCII-encoded payloads, decode them into ZIP archives, and execute next-stage malware. The report also highlighted outbound TCP 1433 MSSQL traffic as a detection opportunity for defenders.
Proofpoint observed a further WhiteShadow campaign delivering Crimson RAT on September 24, 2019. This was the latest specifically dated Crimson delivery listed in the report.
On September 20, 2019, Proofpoint observed WhiteShadow delivering Crimson RAT and also observed NanoCore delivery that day. The activity showed concurrent use of the same delivery mechanism for different malware families.
Proofpoint observed another WhiteShadow campaign delivering Crimson RAT on September 12, 2019. The report notes no evidence linking these Crimson deliveries to prior Crimson campaigns.
Proofpoint observed a WhiteShadow campaign delivering Crimson RAT on September 9, 2019. The delivery was one of several Crimson-related events tracked across August and September 2019.
Proofpoint observed WhiteShadow campaigns delivering NanoCore between September 17 and September 18, 2019. This continued the downloader's use for multiple commodity malware payloads.
Between September 16 and September 18, 2019, Proofpoint observed WhiteShadow delivering AZORult, and between September 16 and September 17 it also delivered Formbook. These campaigns expanded the set of malware families distributed through the downloader.
Between September 2 and September 4, 2019, Proofpoint observed WhiteShadow campaigns delivering NanoCore, njRAT, Agent Tesla, and Crimson. This showed the downloader being used as a multi-malware delivery mechanism rather than for a single payload family.
Proofpoint observed another WhiteShadow campaign delivering Crimson RAT on August 29, 2019. This was part of the early run of WhiteShadow activity documented in the report.
Proofpoint observed a WhiteShadow campaign delivering Crimson RAT on August 26, 2019. The report identifies Crimson as the earliest malware family seen in the WhiteShadow campaigns.
Proofpoint researchers first observed WhiteShadow in malicious Microsoft Word and Excel attachments distributed through email campaigns beginning in August 2019. The staged downloader used Office macros to retrieve next-stage malware from attacker-controlled Microsoft SQL Server infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 79 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.