Skip to content

ShadowPad

ShadowPad is a modular Windows backdoor platform widely used in Chinese espionage operations and notable for its role in several high-profile supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents.

Profile source: Mallory opens in a new tab

ShadowPad

Family profile

ShadowPad is a modular Windows backdoor platform widely used in Chinese espionage operations and notable for its role in several high-profile supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents. It is generally assessed as a successor to PlugX and has been in use since at least 2015, with public reporting beginning in 2017. Unlike openly shared frameworks, ShadowPad is commonly described as a privately sold malware platform with a core backdoor and separately provisioned plugins, which has enabled reuse across multiple distinct threat clusters while complicating attribution.

The malware is designed for long-term covert access on compromised systems. Its architecture uses an obfuscated loader and shellcode-based components to decrypt and load a root plugin and additional modules in memory. ShadowPad supports a virtual file system and configuration storage in the Windows Registry, and it can maintain persistence through mechanisms such as scheduled tasks and DLL sideloading or hijacking with legitimate executables. Reported variants have injected malicious DLLs into legitimate processes such as svchost.exe to evade detection and blend into normal system activity.

Observed ShadowPad functionality includes execution of arbitrary commands and next-stage payloads, plugin-based extensibility, victim profiling, and operational support for broader post-compromise activity. Documented host reconnaissance behaviors include collecting the victim username, domain name, process identifiers, and system date and time. ShadowPad has also been associated with registry-based storage of payloads or configuration data and with delivery of additional tooling during intrusions.

ShadowPad has been linked to numerous China-aligned threat actors and activity clusters, including APT41 and groups tracked as BRONZE ATLAS, BRONZE BUTLER, SparklingGoblin, Tick, Tonto Team, and others. Because the platform is shared among multiple operators, its presence alone is not sufficient for attribution. Campaigns involving ShadowPad have targeted government, telecommunications, industrial, logistics, software, gaming, and critical infrastructure organizations across Asia and beyond, including operations in Pakistan, Afghanistan, India, Hong Kong, Russia, and Argentina.

Delivery and execution patterns vary by campaign. ShadowPad has been distributed through software supply-chain compromises, malicious or trojanized installers, exploitation of public-facing applications such as Microsoft Exchange, and DLL sideloading alongside legitimate software. In several intrusions it served as the primary espionage backdoor, enabling persistent access, follow-on payload execution, credential theft by associated tooling, lateral movement, and data-harvesting operations.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 18, 2026
Last activity
Aug 18, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • CN2

Leading providers

  • CHINA UNICOM China169 Backbone2

Reported operators

Threat actors

40 named in public reporting
APT41

Between mid-2020 and March 2021, an adversary breached 10 power sector organizations and two ports in India, based on analysis of ShadowPad command-and-control traffic by Recorded Future. | “Shadowpad: A Masterpiece Of Privately Sold Malware In Chinese Espionage,” SentinelOne

BRONZE BUTLER

BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB

Tonto

Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors

Earth Lusca

Possible supply chain attack targeting Pakistan government delivers Shadowpad ... Mscoree.dll is a commonly used name for loaders of Shadowpad ... Shadowpad malware keeps being updated and shared among Chinese threat actors

TAG-38

The operation used a trojan called ShadowPad, thought to have links to contractors serving China's Ministry of State Security (MSS).

SparklingGoblin

SparklingGoblin is one of the groups with access to the ShadowPad backdoor.

Hellsing

Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.

Salt Typhoon

The frpc C&C 165.154.227[.]192 could be linked to an SSL certificate ... previously used by ShadowPad, which is another shared tool among several Chinese APT groups.

Threat Group-3390

AvastおよびESETからTmangerファミリに関するブログが公開されました。そこでは特にTmangerとAlbaniiutasについて... LuckyMouseやShadowPadとの関連性が示されています。

BRONZE GENEVA

Cybersecurity researchers have detailed the inner workings of ShadowPad, a sophisticated and modular backdoor that has been adopted by a growing number of Chinese threat groups in recent years... ShadowPad is a remote access trojan capable of maintaining persistent access to compromised computers and executing arbitrary commands and next-stage payloads.

RedEcho

The MSP was compromised by multiple persistent Shadowpad malware infections on multiple internet egress points used by the MSP.

Teleboyi

We have only one domain name that has been used by Shadowpad as a C&C server in both incident response investigations we conducted.

Naikon Team

APT41 used the new builder of shadowpad in 2021, which was mentioned in Ptsecurity’s report

Gamaredon Group

Hunt.io. (2025, April 8). State-Sponsored Tactics: How Gamaredon and ShadowPad Operate and Rotate Their Infrastructure.

RedFoxtrot

The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41.

SteppeDriver

This includes an unreported cluster dubbed SteppeDriver that was first discovered in 2024 and has since targeted entities in France, Mongolia, and South America using tools like ShadowPad, COOLCLIENT, CurlyDoor, RudeGull, and MKTDownloader.

Earth Krahang

Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.

Axiom

ShadowPad is a sophisticated modular remote access trojan (RAT). Though originally developed by Wicked Panda threat actors, ShadowPad is currently used by multiple Chinese state-sponsored threat actor groups.

Glowworm

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

APT17

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

Redfly

ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.

TA428

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

Tropic Trooper

A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.

Icefog

A connection with the ShadowPad backdoor, which is now used by at least five different threat actors, was also found.

Webworm

THREAT ACTOR NAME Webworm (linked: SixLittleMonkeys, FishMonger; cross-tracker: Space Pirates, ShadowPad / SNAPPYBEE)

Shadow-Earth-053

Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.

UAT-7290

The group’s toolset spans Linux implants—RushDrop, DriveSwitch, SilentRaid, and Bulbature—and Windows payloads such as RedLeaves and ShadowPad.

PurpleHaze

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

UNC5174

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

Ke3chang

"...led to the deployment of ShadowPad that's obfuscated using ScatterBrain."

LuoYu

They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX

GALLIUM

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”

APT3

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.”

Mustang Panda

Cisco Talos discovered a malicious campaign that compromised a Taiwanese government-affiliated research institute that started as early as July 2023, delivering the ShadowPad malware, Cobalt Strike and other customized tools for post-compromise activities.

iSoon

"...documents detailing how i-SOON supported the development of the notorious Remote Access Trojan (RAT), ShadowPad."

UNC3886

... deployed ShadowPad, a malware widely shared by Chinese state-sponsored actors.

Jewelbug

"Ink Dragon leverages a custom ShadowPad IIS Listener module to turn compromised servers into active nodes within a distributed mesh..."

Team Tonto

“This latter malware is likely a ShadowPad variant … and even possibly the origin of ShadowPad …” and later: “118.31.3[.]116, recorded by Sentinel One as a ShadowPad C2 … ShadowPad was used by APT41, Team Tonto, Fishmonger, and others.”

Liminal Panda

Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad, both exclusively linked to Chinese hacking groups.

Exploited software

Vulnerabilities linked to ShadowPad

23 CVEs
CVE-2023-46805 Authentication Bypass in Ivanti Connect Secure and Policy Secure CVE-2021-26855 ProxyLogon pre-auth SSRF in Microsoft Exchange Server CVE-2024-21887 Command Injection in Ivanti Connect Secure and Ivanti Policy Secure CVE-2019-9489 Directory Traversal in Trend Micro Apex One, OfficeScan, and Worry-Free Business Security CVE-2020-8468 Content Validation Escape in Trend Micro Apex One, OfficeScan XG, and Worry-Free Business Security Agents CVE-2024-24919 Arbitrary File Read in Check Point Quantum Security Gateways CVE-2021-27065 Post-auth arbitrary file write in Microsoft Exchange Server ECP (ProxyLogon chain) CVE-2021-26858 Arbitrary File Write in Microsoft Exchange Server CVE-2021-26857 Microsoft Exchange Server UMWorkerProcess insecure deserialization RCE CVE-2025-53770 ToolShell unauthenticated RCE in on-premises Microsoft SharePoint Server CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution CVE-2025-8088 WinRAR for Windows NTFS ADS Path Traversal Leading to Arbitrary Code Execution CVE-2025-55182 React2Shell CVE-2026-3502 TrueConf Client Update Integrity Check Bypass Leading to Arbitrary Code Execution CVE-2025-34252 Rejected CVE for NetSarang ShadowPad Supply-Chain Backdoor CVE-2024-8190 OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6 CVE-2024-8963 Authentication Bypass via Path Traversal in Ivanti Cloud Services Appliance CVE-2018-0824 RCE in Microsoft COM for Windows via Improper Handling of Serialized Objects CVE-2021-34523 Microsoft Exchange PowerShell Backend Elevation of Privilege (ProxyShell) CVE-2021-31207 Post-auth Arbitrary File Write in Microsoft Exchange Server (ProxyShell) CVE-2021-34473 ProxyShell pre-auth path confusion in Microsoft Exchange Server CVE-2025-59287 Unauthenticated RCE in Windows Server Update Services GetCookie() CVE-2023-3519 Unauthenticated RCE in Citrix NetScaler ADC and Gateway

MITRE ATT&CK

ShadowPad in ATT&CK

101 distinct techniques

Techniques

101 techniques
T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1195 Supply Chain Compromise T1057 Process Discovery T1112 Modify Registry T1016 System Network Configuration Discovery T1055 Process Injection T1082 System Information Discovery T1033 System Owner/User Discovery T1124 System Time Discovery T1140 Deobfuscate/Decode Files or Information T1071.001 Web Protocols T1090 Proxy T1553.002 Code Signing T1190 Exploit Public-Facing Application T1036 Masquerading T1218 System Binary Proxy Execution T1078.001 Default Accounts T1547.001 Registry Run Keys / Startup Folder T1505.003 Web Shell T1095 Non-Application Layer Protocol T1005 Data from Local System T1119 Automated Collection T1027 Obfuscated Files or Information T1020 Automated Exfiltration T1219 Remote Access Tools T1055.012 Process Hollowing T1574.001 DLL T1572 Protocol Tunneling T1001 Data Obfuscation T1587.001 Malware T1620 Reflective Code Loading T1053.005 Scheduled Task T1059 Command and Scripting Interpreter T1197 BITS Jobs T1041 Exfiltration Over C2 Channel T1543.003 Windows Service T1053 Scheduled Task/Job T1574 Hijack Execution Flow T1059.003 Windows Command Shell T1001.001 Junk Data T1104 Multi-Stage Channels T1568 Dynamic Resolution T1497 Virtualization/Sandbox Evasion T1021 Remote Services T1090.002 External Proxy T1129 Shared Modules T1132 Data Encoding T1056.001 Keylogging T1195.001 Compromise Software Dependencies and Development Tools T1102.001 Dead Drop Resolver T1059.001 PowerShell T1560 Archive Collected Data T1189 Drive-by Compromise T1565 Data Manipulation T1587 Develop Capabilities T1106 Native API T1027.007 Dynamic API Resolution T1021.002 SMB/Windows Admin Shares T1027.010 Command Obfuscation T1072 Software Deployment Tools T1583.001 Domains T1574.013 KernelCallbackTable T1027.002 Software Packing T1557 Adversary-in-the-Middle T1055.001 Dynamic-link Library Injection T1583.004 Server T1027.005 Indicator Removal from Tools T1588.001 Malware T1083 File and Directory Discovery T1012 Query Registry T1070 Indicator Removal T1070.009 Clear Persistence T1568.001 Fast Flux DNS T1113 Screen Capture T1027.001 Binary Padding T1566.001 Spearphishing Attachment T1564.001 Hidden Files and Directories T1047 Windows Management Instrumentation T1203 Exploitation for Client Execution T1573.002 Asymmetric Cryptography T1078.002 Domain Accounts T1090.001 Internal Proxy T1071.004 DNS T1068 Exploitation for Privilege Escalation T1021.001 Remote Desktop Protocol T1133 External Remote Services T1027.011 Fileless Storage T1559.002 Dynamic Data Exchange T1218.011 Rundll32 T1195.002 Compromise Software Supply Chain T1134 Access Token Manipulation T1568.002 Domain Generation Algorithms T1046 Network Service Discovery T1210 Exploitation of Remote Services T1680 Local Storage Discovery T1132.002 Non-Standard Encoding T1029 Scheduled Transfer T1071.002 File Transfer Protocols T1565.001 Stored Data Manipulation T1566 Phishing

Reporting

Research mentioning ShadowPad

Jul 24
Scworld

AI assistant used in cyberattack on Thailand's Ministry of Finance | brief | SC Media

Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.

Jul 24
Security Affairs

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Jul 24
The Hacker News

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Jul 24
Bleeping Computer

Hermes AI agent used to automate attack on Thai Finance Ministry

Jul 23
Cyberveille

Ministère des Finances thaïlandais ciblé par un agent IA autonome Hermes et l'implant Hades | CyberVeille

Jul 23
Huntio

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.