ShadowPad

MITRE ATT&CK: S0596 View on attack.mitre.org

Aliases: POISONPLUG.SHADOW, XShellGhost, ShadowPad

First seen
2017-07-15 00:00:00
Malware type
backdoor, trojan
Family
Malware family
Operating systems
windows
Related IoCs
575 (93 malicious)
Last IoC activity
2026-09-02 00:37:41
Profile updated
2026-07-07 12:51:12

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:de country_code:gb country_code:jp country_code:cn

Context

ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups.

Recent IoC activity

93 malicious indicators in Maltiverse are attributed to ShadowPad (S0596). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.gallant-pike.45-77-153-108.plesk.page 2026-09-03 1
hostname infallible-tereshkova.199-247-22-187.plesk.page 2026-09-03 1
hostname microsoftdesktop.com 2026-09-03 1
hostname bold-hamilton.207-246-119-197.plesk.page 2026-09-03 1
hostname channels.openvista.ma 2026-09-03 1
hostname riwmztda.top 2026-09-02 1
hostname silly-swirles.207-246-119-197.plesk.page 2026-09-02 1
hostname youtubedownloading.com 2026-09-02 1
hostname googlelivenews.com 2026-09-02 1
hostname ec2-16-163-161-107.ap-east-1.compute.amazonaws.com 2026-09-02 1
IP address 5.188.190.252 2026-09-02 6
hostname app30.hema129.com 2026-09-02 1
hostname app40.hema129.com 2026-09-02 1
hostname www.paloaltonetworkhelp.com 2026-09-02 1
hostname static.190.83.78.5.clients.your-server.de 2026-09-02 1
hostname randzalo.com 2026-09-02 1
hostname mgm4adminsi.com 2026-09-02 1
hostname www.shaduruanjian8.com 2026-09-02 1
hostname img.shaduruanjian8.com 2026-09-02 1
hostname shaduruanjian8.com 2026-09-02 1

Detection coverage

  • 2 YARA rules
  • 425 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Fileless Storage (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Scheduled Transfer (attack-pattern)
  • Process Discovery (attack-pattern)
  • DNS (attack-pattern)
  • Non-Standard Encoding (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Injection (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Shadowpad_First_Called_Function (yara-rule)
  • MALPEDIA_Win_Shadowpad_Auto (yara-rule)

Reports & references

  • Trend Micro — Supply Chain Attack Targeting Pakistani Government Delivers Shad (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • ESET — Luckymouse Ta428 Compromise Able Desktop (report)
  • MITRE ATT&CK — G0096 (report)
  • CrowdStrike — Report2021Gtr (report)
  • recordedfuture.com — Redecho Targeting Indian Power Sector (report)
  • therecord.media — Redecho Group Parks Domains After Public Exposure (report)
  • community.riskiq.com — D8B749F2 (report)
  • hello.global.ntt — The Operations Of Winnti Group (report)
  • Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
  • recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
  • sentinelone.com — Sentinelone Sentinellabs Shadowpad Wp V2 (report)
  • pwc.co.uk — Chasing Shadows (report)
  • go.recordedfuture.com — Cta 2023 0808 (report)
  • youtube.com — Watch (report)
  • ESET — Operation Fishmedley (report)
  • Kaspersky — 97937 (report)
  • i.blackhat.com — As 22 Leonsilvia Nextgenplugxshadowpad (report)
  • ESET — Worok Big Picture (report)
  • Broadcom/Symantec — Critical Infrastructure Attacks (report)
  • Broadcom/Symantec — Lancefly Merdoor Zxshell Custom Backdoor (report)
  • jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
  • sentinelone.com — Moshen Dragons Triad And Error Approach Abusing Security Software To Sideload Plugx And Shadowpad (report)
  • Trend Micro — Earth Krahang (report)
  • Trend Micro — Updated Shadowpad Malware Leads To Ransomware Deployment (report)

External references