Last seven days
- First activity
- Aug 18, 2026
- Last activity
- Aug 18, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
ShadowPad is a modular Windows backdoor platform widely used in Chinese espionage operations and notable for its role in several high-profile supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents.
Profile source: Mallory opens in a new tabShadowPad
ShadowPad is a modular Windows backdoor platform widely used in Chinese espionage operations and notable for its role in several high-profile supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents. It is generally assessed as a successor to PlugX and has been in use since at least 2015, with public reporting beginning in 2017. Unlike openly shared frameworks, ShadowPad is commonly described as a privately sold malware platform with a core backdoor and separately provisioned plugins, which has enabled reuse across multiple distinct threat clusters while complicating attribution.
The malware is designed for long-term covert access on compromised systems. Its architecture uses an obfuscated loader and shellcode-based components to decrypt and load a root plugin and additional modules in memory. ShadowPad supports a virtual file system and configuration storage in the Windows Registry, and it can maintain persistence through mechanisms such as scheduled tasks and DLL sideloading or hijacking with legitimate executables. Reported variants have injected malicious DLLs into legitimate processes such as svchost.exe to evade detection and blend into normal system activity.
Observed ShadowPad functionality includes execution of arbitrary commands and next-stage payloads, plugin-based extensibility, victim profiling, and operational support for broader post-compromise activity. Documented host reconnaissance behaviors include collecting the victim username, domain name, process identifiers, and system date and time. ShadowPad has also been associated with registry-based storage of payloads or configuration data and with delivery of additional tooling during intrusions.
ShadowPad has been linked to numerous China-aligned threat actors and activity clusters, including APT41 and groups tracked as BRONZE ATLAS, BRONZE BUTLER, SparklingGoblin, Tick, Tonto Team, and others. Because the platform is shared among multiple operators, its presence alone is not sufficient for attribution. Campaigns involving ShadowPad have targeted government, telecommunications, industrial, logistics, software, gaming, and critical infrastructure organizations across Asia and beyond, including operations in Pakistan, Afghanistan, India, Hong Kong, Russia, and Argentina.
Delivery and execution patterns vary by campaign. ShadowPad has been distributed through software supply-chain compromises, malicious or trojanized installers, exploitation of public-facing applications such as Microsoft Exchange, and DLL sideloading alongside legitimate software. In several intrusions it served as the primary espionage backdoor, enabling persistent access, follow-on payload execution, credential theft by associated tooling, lateral movement, and data-harvesting operations.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Between mid-2020 and March 2021, an adversary breached 10 power sector organizations and two ports in India, based on analysis of ShadowPad command-and-control traffic by Recorded Future. | “Shadowpad: A Masterpiece Of Privately Sold Malware In Chinese Espionage,” SentinelOne
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).
SparklingGoblin is one of the groups with access to the ShadowPad backdoor.
Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.
The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.
AvastおよびESETからTmangerファミリに関するブログが公開されました。そこでは特にTmangerとAlbaniiutasについて... LuckyMouseやShadowPadとの関連性が示されています。
Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.
The MSP was compromised by multiple persistent Shadowpad malware infections on multiple internet egress points used by the MSP.
We have only one domain name that has been used by Shadowpad as a C&C server in both incident response investigations we conducted.
APT41 used the new builder of shadowpad in 2021, which was mentioned in Ptsecurity’s report
Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure.
The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41.
This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
ShadowPad is a sophisticated modular remote access trojan (RAT). Though originally developed by Wicked Panda threat actors, ShadowPad is currently used by multiple Chinese state-sponsored threat actor groups.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.
A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.
THREAT ACTOR NAME Webworm (linked: SixLittleMonkeys, FishMonger; cross-tracker: Space Pirates, ShadowPad / SNAPPYBEE)
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
The group’s toolset spans Linux implants—RushDrop, DriveSwitch, SilentRaid, and Bulbature—and Windows payloads such as RedLeaves and ShadowPad.
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”
Cisco Talos discovered a malicious campaign that compromised a Taiwanese government-affiliated research institute that started as early as July 2023, delivering the ShadowPad malware, Cobalt Strike and other customized tools for post-compromise activities.
"...documents detailing how i-SOON supported the development of the notorious Remote Access Trojan (RAT), ShadowPad."
... deployed ShadowPad, a malware widely shared by Chinese state-sponsored actors.
"Ink Dragon leverages a custom ShadowPad IIS Listener module to turn compromised servers into active nodes within a distributed mesh..."
“This latter malware is likely a ShadowPad variant … and even possibly the origin of ShadowPad …” and later: “118.31.3[.]116, recorded by Sentinel One as a ShadowPad C2 … ShadowPad was used by APT41, Team Tonto, Fishmonger, and others.”
Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad, both exclusively linked to Chinese hacking groups.
Exploited software
MITRE ATT&CK
Reporting
Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.