ShadowPad is a modular Windows backdoor platform widely used in Chinese espionage operations and notable for its role in several high-profile supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents. It is generally assessed as a successor to PlugX and has been in use since at least 2015, with public reporting beginning in 2017. Unlike openly shared frameworks, ShadowPad is commonly described as a privately sold malware platform with a core backdoor and separately provisioned plugins, which has enabled reuse across multiple distinct threat clusters while complicating attribution.
The malware is designed for long-term covert access on compromised systems. Its architecture uses an obfuscated loader and shellcode-based components to decrypt and load a root plugin and additional modules in memory. ShadowPad supports a virtual file system and configuration storage in the Windows Registry, and it can maintain persistence through mechanisms such as scheduled tasks and DLL sideloading or hijacking with legitimate executables. Reported variants have injected malicious DLLs into legitimate processes such as svchost.exe to evade detection and blend into normal system activity.
Observed ShadowPad functionality includes execution of arbitrary commands and next-stage payloads, plugin-based extensibility, victim profiling, and operational support for broader post-compromise activity. Documented host reconnaissance behaviors include collecting the victim username, domain name, process identifiers, and system date and time. ShadowPad has also been associated with registry-based storage of payloads or configuration data and with delivery of additional tooling during intrusions.
ShadowPad has been linked to numerous China-aligned threat actors and activity clusters, including APT41 and groups tracked as BRONZE ATLAS, BRONZE BUTLER, SparklingGoblin, Tick, Tonto Team, and others. Because the platform is shared among multiple operators, its presence alone is not sufficient for attribution. Campaigns involving ShadowPad have targeted government, telecommunications, industrial, logistics, software, gaming, and critical infrastructure organizations across Asia and beyond, including operations in Pakistan, Afghanistan, India, Hong Kong, Russia, and Argentina.
Delivery and execution patterns vary by campaign. ShadowPad has been distributed through software supply-chain compromises, malicious or trojanized installers, exploitation of public-facing applications such as Microsoft Exchange, and DLL sideloading alongside legitimate software. In several intrusions it served as the primary espionage backdoor, enabling persistent access, follow-on payload execution, credential theft by associated tooling, lateral movement, and data-harvesting operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ivanti Connect Secure Authentication Bypass [CVE-2023-46805] ... Allows unauthenticated attackers to bypass authentication controls. Commonly exploited in conjunction with CVE-2024-21887, enabling remote command execution and full system compromise. Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
Some of the victim organizations were breached by exploiting the CVE-2021-26855 vulnerability in Microsoft Exchange... The attackers exploited a known vulnerability in MS Exchange, CVE-2021-26855, as the initial attack vector in several victim organizations. | In mid-October 2021 Kaspersky ICS CERT researchers uncovered an active ShadowPad backdoor infection on industrial control systems (ICS) in Pakistan.
CVE-2024-21887: Vulnerability Type: Command Injection ... Allows remote, unauthenticated attackers to execute commands with elevated privileges, potentially leading to full system compromise ... Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
The first vulnerability they used was CVE-2019-9489, a directory traversal vulnerability in Trend Micro Apex One, OfficeScan and Worry-Free Business Security that was patched in April 2019. | ...some more advanced families, such as the ShadowPad malware used in the NetSarang attacks... Earth Akhlut started to make heavy use of ShadowPad in 2019.
The second vulnerability was CVE-2020-8468, patched in March 2020, a content validation escape vulnerability involving Trend Micro Apex One (on premise) and OfficeScan XG, which was exploited to execute code through a malicious update delivered to selected workstations. | ...some more advanced families, such as the ShadowPad malware used in the NetSarang attacks... Earth Akhlut started to make heavy use of ShadowPad in 2019.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Among our finds on the server were utilities for lateral movement... The server had the following utilities: Utilities to check for and exploit vulnerability MS17-010... The hackers tweaked the functionality of the MS17-010 utility by adding the ability to check an entire subnet.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
The malware payloads seen in campaigns investigated by Microsoft Defender vary from remote access trojans (RATs) like VShell and EtherRAT, the SNOWLIGHT memory-based malware downloader that enabled attackers to deploy more payloads to target environments, ShadowPAD, and XMRig cryptominers. | CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components, Next.js, and related frameworks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-3502 is a flaw in TrueConf Client that allows it to download and install updates without verifying them. Attackers who can tamper with the update source can deliver malicious files, leading to arbitrary code execution on the system.
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. | References include https://securelist.com/shadowpad-in-corporate-networks/81432/ and a Kaspersky press release about 'ShadowPad attackers' hiding a backdoor in software used by hundreds of large companies worldwide. The description states the malicious nssock2.dll implements a multi-stage, DNS-based backdoor.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
“We also discovered that APT41 created a tailored loader to inject a proof-of-concept for CVE-2018-0824 directly into memory, utilizing a remote code execution vulnerability to achieve local privilege escalation.” / “During the compromise the threat actor attempts to exploit CVE-2018-0824, with a tool called UnmarshalPwn …”
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...ShadowPad Malware Actively Exploits WSUS Vulnerability... exploiting CVE-2025-59287 for initial access...
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
27 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Between mid-2020 and March 2021, an adversary breached 10 power sector organizations and two ports in India, based on analysis of ShadowPad command-and-control traffic by Recorded Future. | “Shadowpad: A Masterpiece Of Privately Sold Malware In Chinese Espionage,” SentinelOne
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).
SparklingGoblin is one of the groups with access to the ShadowPad backdoor.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
Insikt Group found network intrusions at seven Indian State Load Dispatch Centers (SLDCs) ... The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Then the malicious DLL... performs the Process Injection technique: Process Hollowing T1055.012.
Several obfuscation techniques are used by the Winnti Group, such as the use of VMProtect and a custom packer.
mscoree.dll is a commonly used name for loaders of Shadowpad ... The MSI metadata mentioned eOffice ... We compared the legitimate eOffice 2.0.3 installer and our backdoored version
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Then the malicious DLL... performs the Process Injection technique: Process Hollowing T1055.012.
The attackers ... are believed to have infiltrated the system via third-party devices like IP cameras that may have been left vulnerable when their default credentials were kept in place.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Telerik.Windows.Data.Validation.dll: copy of applaunch.exe Microsoft file ... One additional CustomAction named “TelerikValidation”
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP. | As the configuration structure shows, the Worker component supports five C2 protocols: TCP, HTTP, HTTPS, TLS and UDP.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The group likely compromised and co-opted internet-facing DVR/IP camera devices for command and control (C2) of ShadowPad malware infections, as well as use of the open source tool FastReverseProxy (FRP).
Both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP.
Technical details | Command and Control TA0011 | Ingress Tool Transfer T1105 | The first step of the attacker on the victim's system is to download legitimate software named meupdate.exe... This software is delivered through the LOLBin utility named certutil.exe. | The ShadowPad backdoor, which is popular among Asian APT groups, is delivered to a victim's computer together with a legitimate executable file. This is known as the Ingress Tool Transfer T1105 technique.
422 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware family referenced because the attacker infrastructure had previously been used as a ShadowPad controller and because it is associated with Chinese espionage activity.
ShadowPad is mentioned as malware previously managed from the same server, indicating historical use of the infrastructure but not as the primary malware in this incident.
Mentioned as historically associated with the server infrastructure used in the operation, contributing to attribution assessment, but not described as the primary malware used in this intrusion.
A known backdoor/platform referenced as previously hosted on the same staging server used by the operator. It is infrastructure-related context, not the main subject of the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.