Skip to content

ShadowPad

ShadowPad is an actively maintained, modular Windows remote-access trojan (RAT) and shellcode-loading framework used extensively in cyberespionage operations associated with China-aligned threat activity.

Profile source: Mallory opens in a new tab

ShadowPad

Family profile

ShadowPad is an actively maintained, modular Windows remote-access trojan (RAT) and shellcode-loading framework used extensively in cyberespionage operations associated with China-aligned threat activity. It has been linked to intrusions involving groups and clusters including APT31/TA412-related activity, UNK_LateNight, FamousSparrow, REF2924, and activity overlapping with Winnti- and ChamelGang-tracked operations. ShadowPad has also been observed in the 2017 CCleaner supply-chain compromise, where it was deployed after attackers gained access to the software vendor’s environment.

ShadowPad is commonly deployed through DLL sideloading, using legitimate executables to load a malicious DLL or loader. Observed loaders can decrypt and execute shellcode in memory, store encrypted payload material for persistence, install services, and inject into legitimate processes. In other operations, ShadowPad established persistence using scheduled tasks. Documented functionality includes remote command execution, Firefox-profile theft, network-traffic collection, and loading or executing additional payloads. Some deployments used defense-evasion measures, including obfuscation and the unhooking of network-monitoring functions.

Recent activity has used spearphishing lures, including defense procurement and request-for-quotation themes, to direct targets to exploitation infrastructure and ultimately deploy ShadowPad through DLL-sideloading chains. Targeting has included U.S. aerospace and defense organizations, government entities, telecommunications providers, technology organizations, diplomatic institutions, and cybersecurity-related organizations. ShadowPad is primarily associated with Windows environments and is used to establish durable post-compromise access for intelligence collection and further intrusion activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 28, 2026
Last activity
Sep 28, 2026
Feed role
C2
Host form
7 IP / 0 hostnames

Leading locations

  • CN6
  • MY1

Leading providers

  • CHINA UNICOM China169 Backbone2
  • Shenzhen Tencent Computer Systems Company Limited2
  • China Unicom Shenzen network1
  • Evoxt Sdn. Bhd.1
  • IDC, China Telecommunications Corporation1

Infrastructure traits

  • Hosting 3

Reported operators

Threat actors

43 named in public reporting
Axiom

12 avril 2017 : Déploiement de ShadowPad sur plusieurs postes et un serveur de build.

UNK_LateNight

Payload : ShadowPad (persistance via tâche planifiée, vol de profil Firefox, collecte trafic réseau).

Salt Typhoon

Multiple artifacts are described as “ShadowPad loader,” while a listed server is identified as a “ShadowPad C&C server.” | Two FmApp.dll samples are described as "ShadowPad loader," and a separate network indicator is labeled "ShadowPad C&C server."

Earth Lusca

Earth Lusca [is] known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families.

Chamelgang

SHADOWPAD is an actively developed and maintained modular remote access toolkit.

APT41

SHADOWPAD is an actively developed and maintained modular remote access toolkit.

REF2924

This environment has already seen the emergence of the REF2924 intrusion set ... as well as the deployment of SHADOWPAD and COBALTSTRIKE.

Earth Naga

Since March 18, 2025, we have identified that Earth Estries has been deploying the ShadowPad backdoor through multiple vectors within the compromised environment.

BRONZE BUTLER

BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB

Tonto

Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors

TAG-38

The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).

SparklingGoblin

SparklingGoblin is one of the groups with access to the ShadowPad backdoor.

Hellsing

Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.

Threat Group-3390

AvastおよびESETからTmangerファミリに関するブログが公開されました。そこでは特にTmangerとAlbaniiutasについて... LuckyMouseやShadowPadとの関連性が示されています。

BRONZE GENEVA

Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.

RedEcho

The MSP was compromised by multiple persistent Shadowpad malware infections on multiple internet egress points used by the MSP.

Teleboyi

We have only one domain name that has been used by Shadowpad as a C&C server in both incident response investigations we conducted.

Naikon

APT41 used the new builder of shadowpad in 2021, which was mentioned in Ptsecurity’s report

Gamaredon Group

Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure.

RedFoxtrot

The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41.

SteppeDriver

This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.

Earth Krahang

Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.

Glowworm

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

APT17

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

Redfly

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

TA428

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

Tropic Trooper

A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.

Icefog

A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.

Webworm

THREAT ACTOR NAME Webworm (linked: SixLittleMonkeys, FishMonger; cross-tracker: Space Pirates, ShadowPad / SNAPPYBEE)

Shadow-Earth-053

Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.

UAT-7290

The group’s toolset spans Linux implants—RushDrop, DriveSwitch, SilentRaid, and Bulbature—and Windows payloads such as RedLeaves and ShadowPad.

PurpleHaze

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

UNC5174

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

Ke3chang

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

LuoYu

They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX

GALLIUM

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”

APT3

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”

Mustang Panda

Cisco Talos discovered a malicious campaign that compromised a Taiwanese government-affiliated research institute that started as early as July 2023, delivering the ShadowPad malware, Cobalt Strike and other customized tools for post-compromise activities.

I-SOON

"...documents detailing how i-SOON supported the development of the notorious Remote Access Trojan (RAT), ShadowPad."

UNC3886

... deployed ShadowPad, a malware widely shared by Chinese state-sponsored actors.

Jewelbug

"Ink Dragon leverages a custom ShadowPad IIS Listener module to turn compromised servers into active nodes within a distributed mesh..."

Liminal Panda

Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad, both exclusively linked to Chinese hacking groups.

Exploited software

Vulnerabilities linked to ShadowPad

26 CVEs
CVE-2026-85046 V8 Type Confusion Remote Code Execution in Google Chrome CVE-2026-87491 Out-of-Bounds Write in Google Chrome V8 CVE-2026-85880 Windows ALPC Heap-Based Buffer Overflow Privilege Escalation CVE-2023-46805 Ivanti Connect Secure and Policy Secure Authentication Bypass CVE-2021-26855 ProxyLogon SSRF in Microsoft Exchange Server CVE-2024-21887 Ivanti Connect Secure and Policy Secure Command Injection CVE-2019-9489 Directory Traversal in Trend Micro Apex One, OfficeScan, and Worry-Free Business Security CVE-2020-8468 Content Validation Escape in Trend Micro Apex One, OfficeScan XG, and Worry-Free Business Security Agents CVE-2024-24919 Arbitrary File Read in Check Point Security Gateways Remote Access VPN and Mobile Access CVE-2021-27065 Microsoft Exchange Server ECP Arbitrary File Write CVE-2021-26858 Post-authentication Arbitrary File Write in Microsoft Exchange Server CVE-2021-26857 Microsoft Exchange Unified Messaging Insecure Deserialization RCE CVE-2025-53770 ToolShell Remote Code Execution in Microsoft SharePoint Server CVE-2017-0144 EternalBlue Windows SMBv1 Remote Code Execution CVE-2025-8088 WinRAR for Windows NTFS ADS Path Traversal CVE-2025-55182 React2Shell: Pre-authentication RCE in React Server Components CVE-2026-3502 TrueConf Client Unverified Update Code Execution CVE-2025-34252 Rejected CVE for NetSarang ShadowPad Supply-Chain Backdoor CVE-2024-8190 OS Command Injection in Ivanti Cloud Services Appliance CVE-2024-8963 Path Traversal Authentication Bypass in Ivanti Cloud Services Appliance CVE-2018-0824 RCE in Microsoft COM for Windows via Improper Handling of Serialized Objects CVE-2021-34523 Microsoft Exchange Server PowerShell Backend Elevation of Privilege CVE-2021-31207 Post-authentication arbitrary file write in Microsoft Exchange Server CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2025-59287 Unauthenticated Remote Code Execution in Windows Server Update Services CVE-2023-3519 Unauthenticated Stack Buffer Overflow RCE in Citrix NetScaler ADC and Gateway

MITRE ATT&CK

ShadowPad in ATT&CK

114 distinct techniques

Techniques

114 techniques
T1195.002 Compromise Software Supply Chain T1056.001 Keylogging T1053.005 Scheduled Task T1539 Steal Web Session Cookie T1555.003 Credentials from Web Browsers T1040 Network Sniffing T1105 Ingress Tool Transfer T1106 Native API T1620 Reflective Code Loading T1027.013 Encrypted/Encoded File T1033 System Owner/User Discovery T1083 File and Directory Discovery T1036.005 Match Legitimate Resource Name or Location T1070.009 Clear Persistence T1082 System Information Discovery T1571 Non-Standard Port T1059.003 Windows Command Shell T1095 Non-Application Layer Protocol T1574.001 DLL T1547.001 Registry Run Keys / Startup Folder T1587.001 Malware T1071.001 Web Protocols T1070.004 File Deletion T1005 Data from Local System T1573.001 Symmetric Cryptography T1041 Exfiltration Over C2 Channel T1027.009 Embedded Payloads T1190 Exploit Public-Facing Application T1036.004 Masquerade Task or Service T1583.004 Server T1543.003 Windows Service T1140 Deobfuscate/Decode Files or Information T1608.001 Upload Malware T1588.001 Malware T1562.001 Disable or Modify Tools T1027 Obfuscated Files or Information T1203 Exploitation for Client Execution T1566 Phishing T1027.007 Dynamic API Resolution T1112 Modify Registry T1055 Process Injection T1078 Valid Accounts T1021.002 SMB/Windows Admin Shares T1071 Application Layer Protocol T1195 Supply Chain Compromise T1057 Process Discovery T1016 System Network Configuration Discovery T1124 System Time Discovery T1090 Proxy T1553.002 Code Signing T1036 Masquerading T1218 System Binary Proxy Execution T1078.001 Default Accounts T1505.003 Web Shell T1119 Automated Collection T1020 Automated Exfiltration T1219 Remote Access Tools T1055.012 Process Hollowing T1572 Protocol Tunneling T1001 Data Obfuscation T1059 Command and Scripting Interpreter T1197 BITS Jobs T1053 Scheduled Task/Job T1574 Hijack Execution Flow T1001.001 Junk Data T1104 Multi-Stage Channels T1568 Dynamic Resolution T1497 Virtualization/Sandbox Evasion T1021 Remote Services T1090.002 External Proxy T1129 Shared Modules T1132 Data Encoding T1195.001 Compromise Software Dependencies and Development Tools T1102.001 Dead Drop Resolver T1059.001 PowerShell T1560 Archive Collected Data T1189 Drive-by Compromise T1565 Data Manipulation T1587 Develop Capabilities T1027.010 Command Obfuscation T1072 Software Deployment Tools T1583.001 Domains T1574.013 KernelCallbackTable T1027.002 Software Packing T1557 Adversary-in-the-Middle T1055.001 Dynamic-link Library Injection T1027.005 Indicator Removal from Tools T1012 Query Registry T1070 Indicator Removal T1568.001 Fast Flux DNS T1113 Screen Capture T1027.001 Binary Padding T1566.001 Spearphishing Attachment T1564.001 Hidden Files and Directories T1047 Windows Management Instrumentation T1573.002 Asymmetric Cryptography T1078.002 Domain Accounts T1090.001 Internal Proxy T1071.004 DNS T1068 Exploitation for Privilege Escalation T1021.001 Remote Desktop Protocol T1133 External Remote Services T1027.011 Fileless Storage T1559.002 Dynamic Data Exchange T1218.011 Rundll32 T1134 Access Token Manipulation T1568.002 Domain Generation Algorithms T1046 Network Service Discovery T1210 Exploitation of Remote Services T1680 Local Storage Discovery T1132.002 Non-Standard Encoding T1029 Scheduled Transfer T1071.002 File Transfer Protocols T1565.001 Stored Data Manipulation

Reporting

Research mentioning ShadowPad

Sep 21
Gurucul Threat Research

Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows | Community Portal | Gurucul

Proofpoint reported that the BlueMoon exploit kit chains three vulnerabilities to compromise Windows systems through Google Chrome: CVE-2026-85046, a V8 arbitrary-code-execution/type-confusion flaw; CVE-2026-87491, a V8 sandbox escape; and CVE-2026-85880, a Windows ALPC local privilege-escalation vulnerability. First observed on August 28 in China-linked TA412 operations targeting U.S. NGOs, mining companies, and commodities-trading firms, the kit was adopted by multiple espionage groups within days, exploiting the gap between Chromium source-code fixes and stable-browser patch deployment. Chinese actors identified as UTA0560 and JungleBamboo (APT31) used the Chrome-to-Windows chain in targeted spear-phishing against NGOs. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE credential-stealing Chrome extension. Organizations should prioritize Chrome and Windows security updates, investigate targeted phishing activity involving Chrome exploitation, and hunt for the named payloads and unauthorized browser extensions, particularly in NGO, mining, and commodities-trading environments.

Sep 21
Xakep

Сразу четыре хак-группы пользуются эксплоит-китом BlueMoon - Хакер

Sep 9
Volexity

Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows | Volexity

Multiple espionage-focused threat clusters have adopted the BlueMoon exploit kit, chaining Chromium V8 vulnerabilities, a V8 sandbox escape, and the Windows kernel privilege-escalation flaw CVE-2026-85880 to gain code execution and elevated privileges. Older Windows 10 and Windows Server 2019/2022 builds are reported to be particularly exposed. The activity begins with phishing and has targeted U.S. NGOs, mining and commodity-trading firms, as well as government, defense, aerospace, manufacturing, financial, and commercial organizations across the United States and Southeast Asia. TA412, also tracked as Violet Typhoon and APT31, was the first identified user and used phishing to install the GemStone malicious browser extension. Additional clusters—UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket—have reportedly used the kit to deliver browser-surveillance payloads, ShadowPad, and other loaders. Proofpoint assessed that rapid adoption by several actors, exposed development artifacts, and exploitation during patch gaps suggest a shared exploit-procurement pipeline; AI-assisted development may also have lowered the barrier to weaponizing browser exploits.

Sep 9
Cyber Security News

Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks

Sep 9
Cryptika

Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks | Cryptika Cybersecurity

Sep 9
The Hacker News

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Aug 26
Tenable

Tenable & SentinelOne: 93 CVEs Expose Edge Risk | Tenable®

SentinelLABS disrupted multiple China-nexus cyberespionage campaigns between June 2024 and March 2025 targeting SentinelOne, a South Asian government entity, a European media organization, and more than 70 other victims. The ShadowPad and PurpleHaze clusters used chained zero-days in edge appliances, including CVE-2024-8963 and CVE-2024-8190, alongside ShadowPad malware protected by ScatterBrain/ScatterBee obfuscation, the Go-based GOREshell reverse-SSH backdoor, Nimbo-C2, operational relay box networks, and log removal. SentinelOne reported that it was not compromised. A joint Tenable-SentinelOne review shows that this activity reflects a broader cross-actor pattern: 93 CVE-to-actor attribution pairs across 82 vulnerabilities converged on all seven identified edge-device vendors, despite only 21% overlap in the CVEs tracked independently. Twelve flaws have confirmed exploitation by multiple China-, Russia-, DPRK-, or Iran-linked groups and ransomware operators. F5, Citrix, and Ivanti EPMM and Connect Secure deployments face recurring exposure and exploitation; organizations should prioritize edge-device patching, disable unnecessary features, continuously monitor remote-access systems, and use segmentation and other defense-in-depth controls to limit lateral movement after a breach.

Aug 19
Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.