ShadowPad is a privately sold, modular Windows backdoor used by multiple China-linked threat actors for cyberespionage and long-term remote access. It emerged in 2015 and became widely known following the 2017 NetSarang software supply-chain compromise. Its operators include APT41, Tonto Team, and Fishmonger. Shared use across threat groups means that detecting ShadowPad alone does not establish attribution. Victims span government, telecommunications, manufacturing, finance, education, research, technology, and other sectors worldwide.
ShadowPad uses a core module to load and manage encrypted plugins in memory, allowing operators to add or remove functionality at runtime. Available modules support remote command execution, file transfer, process and service management, registry operations, host inventory, port mapping, keylogging, screenshot capture, and remote-desktop interaction. Observed deployments also collect browser profile data and capture network traffic. Command-and-control options include TCP, UDP, HTTP, HTTPS, and DNS, with newer variants supporting DNS over HTTPS. Some versions use generated domains or remotely retrieved addresses to maintain connectivity.
Execution commonly relies on DLL sideloading through legitimate signed applications, followed by decryption and in-memory loading of the backdoor. ShadowPad injects components into legitimate Windows processes and establishes persistence through services, scheduled tasks, or registry autorun settings. Encrypted registry-backed storage can hold plugins, configuration, and payloads. Defensive-evasion features include custom executable loading, obfuscated imports and strings, anti-debugging checks, machine-specific payload encryption, and deletion of on-disk payloads. An analyzed version also supports a UAC-bypass execution mode.
Delivery has included compromised software distributions, spearphishing, browser exploit kits, and deployment after exploitation of exposed enterprise services. Documented intrusion chains exploited Microsoft Exchange ProxyLogon vulnerabilities and the WSUS vulnerability CVE-2025-59287. Operators frequently deploy ShadowPad on high-privilege systems, including domain controllers, to support reconnaissance, lateral movement, surveillance, and data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Beginning October 22, 2025, threat actors rapidly weaponized the publicly released proof-of-concept exploit for CVE-2025-59287 to target WSUS servers exposed on TCP ports 8530 and 8531.
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
A sophisticated cyberattack campaign, identified in November 2025, leverages a critical vulnerability in Microsoft Windows Server Update Services (WSUS) to deploy ShadowPad, a highly modular backdoor malware used extensively by Chinese state-sponsored APT groups for espionage operations.
The first exploit targets CVE-2026-85046 in V8's optimizing compilers. When an array's element type changes during sorting, the optimized code can treat a value as the wrong type.
That DLL checks the Windows build again, then tries CVE-2026-85880. The exploit uses the ALPC communication and WNF notification mechanisms to gain kernel read/write access.
The next exploit, CVE-2026-87491, escapes the V8 sandbox. BlueMoon corrupts WebAssembly metadata and replaces compiled function code with the p1 shellcode.
In 2020, they exploited CVE-2019-9489 and CVE-2020-8468 in Trend Micro’s security solutions that were exposed to the Internet, in order to deliver ShadowPad into internal networks for further exploitation. | ShadowPad is a privately sold modular malware platform –rather than an open attack framework– with plugins sold separately.
In 2020, they exploited CVE-2019-9489 and CVE-2020-8468 in Trend Micro’s security solutions that were exposed to the Internet, in order to deliver ShadowPad into internal networks for further exploitation. | ShadowPad is a privately sold modular malware platform –rather than an open attack framework– with plugins sold separately.
Ivanti Connect Secure Authentication Bypass [CVE-2023-46805] ... Allows unauthenticated attackers to bypass authentication controls. Commonly exploited in conjunction with CVE-2024-21887, enabling remote command execution and full system compromise. Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
CVE-2024-21887: Vulnerability Type: Command Injection ... Allows remote, unauthenticated attackers to execute commands with elevated privileges, potentially leading to full system compromise ... Trend Micro’s report on Earth Estries/Salt Typhoon states that the group actively exploits Ivanti Connect Secure VPN flaws to establish initial access ... | The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The attacks resulted in the ShadowPad loader being implanted"; separate unattributed ShadowPad activity affected a software development company and a real estate company.
They stole source code, software code signing certificates, customer account data, personally identifiable information, and deployed sophisticated supply-chain attacks [CCleaner, ShadowPad, ShadowHammer], the indictment reveals.
In UNK_LateNight's campaign, the DLL decrypts A08744D2.tmp with AES and loads ShadowPad, a backdoor that steals Firefox profile data and captures network traffic.
The attackers use well-known malware, such as PlugX, ShadowPad, Poison Ivy.
Both incidents involved Shadowpad, a malware family that has been used by multiple advanced Chinese threat actors to perform espionage.
ShadowPad is a privately sold modular malware platform –rather than an open attack framework– with plugins sold separately.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
ShadowPad communicates over HTTP/HTTPS to C2 servers using spoofed browser headers to blend with legitimate traffic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
493 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware delivered through BlueMoon in espionage-focused campaigns. The content does not describe its specific functionality.
A backdoor delivered through BlueMoon in UNK_LateNight's campaign using DLL sideloading and an AES-encrypted payload. It steals Firefox profile data, captures network traffic, and communicates over HTTPS. The campaign's infection chain uses the EdgeCore_AutoUpdate scheduled task for persistence.
Remote-access trojan/backdoor reportedly deployed on Piriform workstations and a build server during the intrusion preceding the CCleaner supply-chain compromise.
Backdoor providing scheduled-task persistence, Firefox-profile theft, and network-traffic collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.