shadowpad
ShadowPad is malware/tooling referenced in the provided content in connection with advanced intrusion activity and a later campaign exploiting a Microsoft WSUS remote code execution vulnerability (CVE-2025-59287). The content associates related DLL sideloading activity with ShadowPad, also referred to in one cited context as “NetSarang.” Reported activity targeted government organizations in Asia, and the report notes that DLL sideloading has historically been a favored technique of China-based APT groups, but the content does not directly and conclusively attribute ShadowPad itself to a specific state. In the detailed intrusion reporting, activity linked elsewhere to ShadowPad/NetSarang involved repeated DLL sideloading using legitimate signed applications including Cisco Webex components, VLC Media Player, Razer Chromium Render Process, Microsoft Symbol Server Builder, and a Bitdefender Crash Handler executable. The cases described shared infrastructure, loader shellcode, and code-flow obfuscation. Observed behaviors included encrypted plugin loading, reverse shell execution, process hollowing, UAC bypass via CMSTPLUA and via fodhelper.exe/ComputerDefaults.exe, service creation, autorun persistence, and anti-security actions such as attempting to stop Kaspersky avp.exe. One case involved a USB worm that propagated via removable drives. VirusTotal hunting linked 2022 activity to related 2021 samples, including a sideloading chain previously reported in association with ShadowPad or NetSarang. Separately, the content states that ShadowPad malware was used in attacks exploiting WSUS RCE vulnerability CVE-2025-59287 and that the campaign used the vulnerability to establish persistence on compromised systems.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ShadowPad is involved in attacks exploiting a WSUS remote code execution vulnerability (CVE-2025-59287), likely for espionage or supply chain compromise.
ShadowPad is involved in attacks exploiting a WSUS remote code execution vulnerability (CVE-2025-59287).
ShadowPad is being used in attacks exploiting a newly patched WSUS remote code execution vulnerability (CVE-2025-59287).
Mentioned in connection with a VirusTotal-hunted sideloading case that used Bitdefender Crash Handler and encrypted .dat payloads; the article suggests a possible connection between that case and the 2022 campaigns due to shared obfuscation and shellcode loader characteristics.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.