Last seven days
- First activity
- Sep 28, 2026
- Last activity
- Sep 28, 2026
- Feed role
- C2
- Host form
- 7 IP / 0 hostnames
ShadowPad is an actively maintained, modular Windows remote-access trojan (RAT) and shellcode-loading framework used extensively in cyberespionage operations associated with China-aligned threat activity.
Profile source: Mallory opens in a new tabShadowPad
ShadowPad is an actively maintained, modular Windows remote-access trojan (RAT) and shellcode-loading framework used extensively in cyberespionage operations associated with China-aligned threat activity. It has been linked to intrusions involving groups and clusters including APT31/TA412-related activity, UNK_LateNight, FamousSparrow, REF2924, and activity overlapping with Winnti- and ChamelGang-tracked operations. ShadowPad has also been observed in the 2017 CCleaner supply-chain compromise, where it was deployed after attackers gained access to the software vendor’s environment.
ShadowPad is commonly deployed through DLL sideloading, using legitimate executables to load a malicious DLL or loader. Observed loaders can decrypt and execute shellcode in memory, store encrypted payload material for persistence, install services, and inject into legitimate processes. In other operations, ShadowPad established persistence using scheduled tasks. Documented functionality includes remote command execution, Firefox-profile theft, network-traffic collection, and loading or executing additional payloads. Some deployments used defense-evasion measures, including obfuscation and the unhooking of network-monitoring functions.
Recent activity has used spearphishing lures, including defense procurement and request-for-quotation themes, to direct targets to exploitation infrastructure and ultimately deploy ShadowPad through DLL-sideloading chains. Targeting has included U.S. aerospace and defense organizations, government entities, telecommunications providers, technology organizations, diplomatic institutions, and cybersecurity-related organizations. ShadowPad is primarily associated with Windows environments and is used to establish durable post-compromise access for intelligence collection and further intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
12 avril 2017 : Déploiement de ShadowPad sur plusieurs postes et un serveur de build.
Payload : ShadowPad (persistance via tâche planifiée, vol de profil Firefox, collecte trafic réseau).
Multiple artifacts are described as “ShadowPad loader,” while a listed server is identified as a “ShadowPad C&C server.” | Two FmApp.dll samples are described as "ShadowPad loader," and a separate network indicator is labeled "ShadowPad C&C server."
Earth Lusca [is] known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families.
SHADOWPAD is an actively developed and maintained modular remote access toolkit.
SHADOWPAD is an actively developed and maintained modular remote access toolkit.
This environment has already seen the emergence of the REF2924 intrusion set ... as well as the deployment of SHADOWPAD and COBALTSTRIKE.
Since March 18, 2025, we have identified that Earth Estries has been deploying the ShadowPad backdoor through multiple vectors within the compromised environment.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors
The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).
SparklingGoblin is one of the groups with access to the ShadowPad backdoor.
Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.
AvastおよびESETからTmangerファミリに関するブログが公開されました。そこでは特にTmangerとAlbaniiutasについて... LuckyMouseやShadowPadとの関連性が示されています。
Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.
The MSP was compromised by multiple persistent Shadowpad malware infections on multiple internet egress points used by the MSP.
We have only one domain name that has been used by Shadowpad as a C&C server in both incident response investigations we conducted.
APT41 used the new builder of shadowpad in 2021, which was mentioned in Ptsecurity’s report
Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure.
The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41.
This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.
A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.
THREAT ACTOR NAME Webworm (linked: SixLittleMonkeys, FishMonger; cross-tracker: Space Pirates, ShadowPad / SNAPPYBEE)
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
The group’s toolset spans Linux implants—RushDrop, DriveSwitch, SilentRaid, and Bulbature—and Windows payloads such as RedLeaves and ShadowPad.
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."
They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”
Cisco Talos discovered a malicious campaign that compromised a Taiwanese government-affiliated research institute that started as early as July 2023, delivering the ShadowPad malware, Cobalt Strike and other customized tools for post-compromise activities.
"...documents detailing how i-SOON supported the development of the notorious Remote Access Trojan (RAT), ShadowPad."
... deployed ShadowPad, a malware widely shared by Chinese state-sponsored actors.
"Ink Dragon leverages a custom ShadowPad IIS Listener module to turn compromised servers into active nodes within a distributed mesh..."
Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad, both exclusively linked to Chinese hacking groups.
Exploited software
MITRE ATT&CK
Reporting
Proofpoint reported that the BlueMoon exploit kit chains three vulnerabilities to compromise Windows systems through Google Chrome: CVE-2026-85046, a V8 arbitrary-code-execution/type-confusion flaw; CVE-2026-87491, a V8 sandbox escape; and CVE-2026-85880, a Windows ALPC local privilege-escalation vulnerability. First observed on August 28 in China-linked TA412 operations targeting U.S. NGOs, mining companies, and commodities-trading firms, the kit was adopted by multiple espionage groups within days, exploiting the gap between Chromium source-code fixes and stable-browser patch deployment. Chinese actors identified as UTA0560 and JungleBamboo (APT31) used the Chrome-to-Windows chain in targeted spear-phishing against NGOs. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE credential-stealing Chrome extension. Organizations should prioritize Chrome and Windows security updates, investigate targeted phishing activity involving Chrome exploitation, and hunt for the named payloads and unauthorized browser extensions, particularly in NGO, mining, and commodities-trading environments.
Multiple espionage-focused threat clusters have adopted the BlueMoon exploit kit, chaining Chromium V8 vulnerabilities, a V8 sandbox escape, and the Windows kernel privilege-escalation flaw CVE-2026-85880 to gain code execution and elevated privileges. Older Windows 10 and Windows Server 2019/2022 builds are reported to be particularly exposed. The activity begins with phishing and has targeted U.S. NGOs, mining and commodity-trading firms, as well as government, defense, aerospace, manufacturing, financial, and commercial organizations across the United States and Southeast Asia. TA412, also tracked as Violet Typhoon and APT31, was the first identified user and used phishing to install the GemStone malicious browser extension. Additional clusters—UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket—have reportedly used the kit to deliver browser-surveillance payloads, ShadowPad, and other loaders. Proofpoint assessed that rapid adoption by several actors, exposed development artifacts, and exploitation during patch gaps suggest a shared exploit-procurement pipeline; AI-assisted development may also have lowered the barrier to weaponizing browser exploits.
SentinelLABS disrupted multiple China-nexus cyberespionage campaigns between June 2024 and March 2025 targeting SentinelOne, a South Asian government entity, a European media organization, and more than 70 other victims. The ShadowPad and PurpleHaze clusters used chained zero-days in edge appliances, including CVE-2024-8963 and CVE-2024-8190, alongside ShadowPad malware protected by ScatterBrain/ScatterBee obfuscation, the Go-based GOREshell reverse-SSH backdoor, Nimbo-C2, operational relay box networks, and log removal. SentinelOne reported that it was not compromised. A joint Tenable-SentinelOne review shows that this activity reflects a broader cross-actor pattern: 93 CVE-to-actor attribution pairs across 82 vulnerabilities converged on all seven identified edge-device vendors, despite only 21% overlap in the CVEs tracked independently. Twelve flaws have confirmed exploitation by multiple China-, Russia-, DPRK-, or Iran-linked groups and ransomware operators. F5, Citrix, and Ivanti EPMM and Connect Secure deployments face recurring exposure and exploitation; organizations should prioritize edge-device patching, disable unnecessary features, continuously monitor remote-access systems, and use segmentation and other defense-in-depth controls to limit lateral movement after a breach.
A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.